HackerOne Disclosed Reports - 2026-08-24

0 Replies, 9 Views

Logo
Low
resolved

@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)


Bug reported by A3z4km3 was disclosed at August 25, 2026, 2:09 am   |   Cross-site Scripting (XSS) - Generic

An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.


Logo
Medium
resolved

URI scheme validation bypass in ActionText `to_markdown` via user-supplied `` marker tag


Bug reported by offset was disclosed at August 24, 2026, 4:21 pm   |   Cross-site Scripting (XSS) - Reflected


Logo
Medium
resolved

Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider


Bug reported by Michael Liu was disclosed at August 24, 2026, 1:23 am   |   Path Traversal

A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-08-24 - by hashXploiter - Yesterday, 12:30 PM



Users browsing this thread: 1 Guest(s)