HackerOne Disclosed Reports - 2026-08-14

0 Replies, 3 Views

Logo
Medium
resolved

TaskProcessing callback authorization bypass allows ex-members to post as Assistant Talk Bot


Bug reported by 野口晋義(Kuniyoshi Noguchi) was disclosed at August 14, 2026, 2:50 pm   |   Insecure Direct Object Reference (IDOR)

An authenticated user could inject messages into Talk conversations they no longer had access to by scheduling a text processing task with a callback targeting the Assistant Talk Bot. The bot did not verify that the user still had access to the target conversation before posting messages under its trusted identity. The vulnerability was fixed in Assistant Talk Bot version 3.3.0 by limiting bot replies to active conversation participants only.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-08-14 - by hashXploiter - 2 hours ago



Users browsing this thread: 1 Guest(s)