HackerOne Disclosed Reports - 2026-09-16

0 Replies, 6 Views

Logo
Medium
resolved

Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections


Bug reported by Balvant Chavda was disclosed at September 17, 2026, 6:22 am   |   Server-Side Request Forgery (SSRF)

A blind SSRF vulnerability was discovered in the Circles app for Nextcloud. The vulnerability allowed unauthenticated users to force the server to fetch internal URLs, bypassing local-address protections in Nextcloud. The vulnerability was caused by the Circles app's signature verification process, which fetched an attacker-provided URL before trust was established.


Logo
Low
resolved

Team membership information returned on API level based on ID


Bug reported by Melanie was disclosed at September 17, 2026, 5:49 am   |   Insecure Direct Object Reference (IDOR)

A vulnerability was discovered in the Nextcloud Circles app that allowed any authenticated user to access membership information for any circle and user combination, regardless of their authorization. The issue stemmed from a lack of permission checks in the affected service and request classes, as well as the public exposure of the vulnerable functionality through an API endpoint. This vulnerability could have led to the disclosure of sensitive organizational data, including private circle memberships, inheritance relationships, and user identification details.


Logo
High
resolved

Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags


Bug reported by Sergio Garcia was disclosed at September 16, 2026, 8:57 pm   |   OS Command Injection

The Bedrock AgentCore Python SDK was found to have an incomplete input sanitization vulnerability in the `install_packages()` method. The sanitization process failed to properly handle certain pip flags, such as `--index-url`, which allowed arbitrary command execution within the Code Interpreter sandbox. This vulnerability was discovered to affect all versions of the `bedrock-agentcore-sdk-python` up to at least v1.4.8.


Logo
High
resolved

Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change


Bug reported by usagirabbit was disclosed at September 16, 2026, 9:16 am   |   Business Logic Errors

A vulnerability was discovered in Monero's wallet code that allowed a malicious or compromised hot/watch-only wallet with the victim wallet's private view key to forge an authenticated unsigned transaction. The forged transaction included an attacker-controlled output that was presented as change, and the offline signer then reconstructed and signed that output as change. This resulted in a direct loss-of-funds issue, as the resulting output was attacker-spendable and not victim-spendable.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-09-16 - by hashXploiter - 2 hours ago



Users browsing this thread: 1 Guest(s)