<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Dark C0d3rs - All Forums]]></title>
		<link>https://darkcoders.wiki/</link>
		<description><![CDATA[Dark C0d3rs - https://darkcoders.wiki]]></description>
		<pubDate>Sat, 08 Aug 2026 04:26:15 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-08-05]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-05</link>
			<pubDate>Thu, 06 Aug 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-05</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/0p8e6gg8xoy45dhjxs5wh4iti6k8/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3782701' style='color: #4aa3ff;' target='new'>Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift &#36;where)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/griffinf?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at August 5, 2026, 3:50 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '&#36;where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in the exposure of sensitive information such as database credentials, deployment access tokens, and encryption keys. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3699522' style='color: #4aa3ff;' target='new'>`check_reserve_proof` counts duplicate entries: one output can inflate `total`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the `check_reserve_proof` function in the Monero wallet software. The vulnerability allowed duplicate entries in the reserve proof, which could artificially inflate the reported total reserve amount without affecting the verification of individual entries. The issue was in the verifier logic, where the accounting was done in a flat manner, adding the output amount for each row without checking for duplicates. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3698862' style='color: #4aa3ff;' target='new'> `check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Missing Required Cryptographic Step</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `check_reserve_proof` function in the Monero codebase was found to sum RingCT ECDH amounts without checking the output commitment. The decoded amount was added to the total without verifying that it matched the commitment, which could allow a malicious prover to claim larger reserves than actually exist on-chain. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3693636' style='color: #4aa3ff;' target='new'>wallet-rpc crash via malformed /gettransactions response (empty txs → vector::front() in check_tx_key / check_tx_proof)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>NULL Pointer Dereference</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Monero wallet software that could cause the wallet-rpc process to crash when handling a malformed response from the daemon's /gettransactions endpoint. The vulnerability was due to the wallet software making assumptions about the response structure that were not always valid, leading to undefined behavior when attempting to access empty data structures. The crash occurred when the wallet software tried to retrieve metadata from the empty response, causing a segmentation fault. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3700036' style='color: #4aa3ff;' target='new'>SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Missing Required Cryptographic Step</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Monero project where the get_spend_proof and check_spend_proof functions do not verify the returned transaction hash against the requested transaction ID. This allows a malicious or compromised daemon to provide a valid serialized transaction body for a different transaction than the one requested, which can be used to create or verify a spend proof for that different transaction. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723315' style='color: #4aa3ff;' target='new'>wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Array Index Underflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The wallet-rpc method "describe_transfer" was found to use the wrong index when retrieving information about the ring members for each input. Instead of using the "real_output" index, which represents the position of the real entry in the ring, it used the "real_output_in_tx_index", which represents the position of the output in the source transaction. This resulted in the pre-sign review displaying the wrong information about the ring members to the cold-wallet operator. The signing process itself was not affected, as the correct ring members were used when constructing the transaction. The vulnerability was present in the master branch and the release-v0.18 branch of the monero-project/monero repository. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3687543' style='color: #4aa3ff;' target='new'> `relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/benisprlh?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 5:05 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. This vulnerability was introduced in the master branch and was present at the time of the commit analyzed. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/0p8e6gg8xoy45dhjxs5wh4iti6k8/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3782701' style='color: #4aa3ff;' target='new'>Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift &#36;where)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/griffinf?type=user' style='color: #4aa3ff;' target='new'> <strong> Griffin</strong></a> was disclosed at August 5, 2026, 3:50 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Code Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '&#36;where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in the exposure of sensitive information such as database credentials, deployment access tokens, and encryption keys. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3699522' style='color: #4aa3ff;' target='new'>`check_reserve_proof` counts duplicate entries: one output can inflate `total`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the `check_reserve_proof` function in the Monero wallet software. The vulnerability allowed duplicate entries in the reserve proof, which could artificially inflate the reported total reserve amount without affecting the verification of individual entries. The issue was in the verifier logic, where the accounting was done in a flat manner, adding the output amount for each row without checking for duplicates. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3698862' style='color: #4aa3ff;' target='new'> `check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Missing Required Cryptographic Step</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `check_reserve_proof` function in the Monero codebase was found to sum RingCT ECDH amounts without checking the output commitment. The decoded amount was added to the total without verifying that it matched the commitment, which could allow a malicious prover to claim larger reserves than actually exist on-chain. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3693636' style='color: #4aa3ff;' target='new'>wallet-rpc crash via malformed /gettransactions response (empty txs → vector::front() in check_tx_key / check_tx_proof)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>NULL Pointer Dereference</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Monero wallet software that could cause the wallet-rpc process to crash when handling a malformed response from the daemon's /gettransactions endpoint. The vulnerability was due to the wallet software making assumptions about the response structure that were not always valid, leading to undefined behavior when attempting to access empty data structures. The crash occurred when the wallet software tried to retrieve metadata from the empty response, causing a segmentation fault. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3700036' style='color: #4aa3ff;' target='new'>SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Missing Required Cryptographic Step</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Monero project where the get_spend_proof and check_spend_proof functions do not verify the returned transaction hash against the requested transaction ID. This allows a malicious or compromised daemon to provide a valid serialized transaction body for a different transaction than the one requested, which can be used to create or verify a spend proof for that different transaction. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723315' style='color: #4aa3ff;' target='new'>wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/bebensap?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 10:23 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Array Index Underflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The wallet-rpc method "describe_transfer" was found to use the wrong index when retrieving information about the ring members for each input. Instead of using the "real_output" index, which represents the position of the real entry in the ring, it used the "real_output_in_tx_index", which represents the position of the output in the source transaction. This resulted in the pre-sign review displaying the wrong information about the ring members to the cold-wallet operator. The signing process itself was not affected, as the correct ring members were used when constructing the transaction. The vulnerability was present in the master branch and the release-v0.18 branch of the monero-project/monero repository. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3687543' style='color: #4aa3ff;' target='new'> `relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/benisprlh?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 5:05 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. This vulnerability was introduced in the master branch and was present at the time of the commit analyzed. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-08-04]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-04</link>
			<pubDate>Wed, 05 Aug 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-04</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3687543' style='color: #4aa3ff;' target='new'> `relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/benisprlh?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 5:05 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. This vulnerability was introduced in the master branch and was present at the time of the commit analyzed. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3687543' style='color: #4aa3ff;' target='new'> `relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/benisprlh?type=user' style='color: #4aa3ff;' target='new'> <strong> Beni Saprulah</strong></a> was disclosed at August 5, 2026, 5:05 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. This vulnerability was introduced in the master branch and was present at the time of the commit analyzed. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-08-03]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-03</link>
			<pubDate>Tue, 04 Aug 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-03</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3478646' style='color: #4aa3ff;' target='new'>GitHub Retired UsernameTakeover From  [aws/████████]</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sh3d0w?type=user' style='color: #4aa3ff;' target='new'> <strong> Shad0w</strong></a> was disclosed at August 3, 2026, 6:17 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Inclusion of Functionality from Untrusted Control Sphere</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A retired GitHub username was discovered to be unclaimed, allowing an attacker to register the username and create a repository with the same name as the original. As a result, the original link to the repository now points to the attacker-controlled repository, enabling a persistent repository hijack. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3514640' style='color: #4aa3ff;' target='new'>Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/howtoplay?type=user' style='color: #4aa3ff;' target='new'> <strong> s</strong></a> was disclosed at August 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Path Traversal</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3478646' style='color: #4aa3ff;' target='new'>GitHub Retired UsernameTakeover From  [aws/████████]</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sh3d0w?type=user' style='color: #4aa3ff;' target='new'> <strong> Shad0w</strong></a> was disclosed at August 3, 2026, 6:17 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Inclusion of Functionality from Untrusted Control Sphere</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A retired GitHub username was discovered to be unclaimed, allowing an attacker to register the username and create a repository with the same name as the original. As a result, the original link to the repository now points to the attacker-controlled repository, enabling a persistent repository hijack. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3514640' style='color: #4aa3ff;' target='new'>Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/howtoplay?type=user' style='color: #4aa3ff;' target='new'> <strong> s</strong></a> was disclosed at August 3, 2026, 1:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Path Traversal</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Xalgorix — Open-source AI pentester]]></title>
			<link>https://darkcoders.wiki/Thread-Xalgorix-%E2%80%94-Open-source-AI-pentester</link>
			<pubDate>Sun, 02 Aug 2026 13:30:56 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-Xalgorix-%E2%80%94-Open-source-AI-pentester</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Xalgorix — Open-source AI pentester that proves vulnerabilities</span></span></div>
Most scanners detect. Xalgorix proves. An autonomous LLM agent works a full pentest methodology, then an independent verifier re-exploits every finding before it's reported — so you get proof, not a pile of maybes to triage. Self-hosted, private, and bring-your-own-LLM. Built in Go + TypeScript.<br />
<br />
<img src="https://raw.githubusercontent.com/xalgorix/xalgorix/refs/heads/main/assets/banner.png" loading="lazy"  alt="[Image: banner.png]" class="mycode_img" /><br />
<br />
Link: You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view.]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align"><span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Xalgorix — Open-source AI pentester that proves vulnerabilities</span></span></div>
Most scanners detect. Xalgorix proves. An autonomous LLM agent works a full pentest methodology, then an independent verifier re-exploits every finding before it's reported — so you get proof, not a pile of maybes to triage. Self-hosted, private, and bring-your-own-LLM. Built in Go + TypeScript.<br />
<br />
<img src="https://raw.githubusercontent.com/xalgorix/xalgorix/refs/heads/main/assets/banner.png" loading="lazy"  alt="[Image: banner.png]" class="mycode_img" /><br />
<br />
Link: You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-08-01]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-01</link>
			<pubDate>Sun, 02 Aug 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-08-01</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/t5bperr6a46huf3g9yn98it5zpfz/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3878586' style='color: #4aa3ff;' target='new'>Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/its9me?type=user' style='color: #4aa3ff;' target='new'> <strong> Ali Khaled</strong></a> was disclosed at August 1, 2026, 12:27 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the payment, and ignored the donor's current privacy settings as well as the recipient's opt-in gate. This resulted in the exposure of donations that the donor had since made private or secret. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/t5bperr6a46huf3g9yn98it5zpfz/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3878586' style='color: #4aa3ff;' target='new'>Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/its9me?type=user' style='color: #4aa3ff;' target='new'> <strong> Ali Khaled</strong></a> was disclosed at August 1, 2026, 12:27 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the payment, and ignored the donor's current privacy settings as well as the recipient's opt-in gate. This resulted in the exposure of donations that the donor had since made private or secret. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-31]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-31</link>
			<pubDate>Sat, 01 Aug 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-31</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723248' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Connection: close<TAB> in Node.js llhttp parser</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nadav0077?type=user' style='color: #4aa3ff;' target='new'> <strong> Nadav Magier</strong></a> was disclosed at July 31, 2026, 3:27 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>HTTP Request Smuggling</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Node.js HTTP server where it ignores the "Connection: close" header when the token is followed by a tab character. This allows an attacker to send a second request on the same connection, even after the first request should have closed the connection. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/mkepvaoi246x9gzrqwg0kagw6pqb/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3644182' style='color: #4aa3ff;' target='new'>Stored XSS in nameserver field on account settings page</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/axolot23?type=user' style='color: #4aa3ff;' target='new'> <strong> Axolot</strong></a> was disclosed at July 31, 2026, 3:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stored XSS vulnerability was discovered in the nameserver field on the account settings page. The lack of input validation and weak CSP configuration allowed the injection of malicious JavaScript code that executed when the settings page was reloaded. The vulnerability was limited to a self-XSS scenario, affecting only the account owner who injected the payload and not other users. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3723248' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Connection: close<TAB> in Node.js llhttp parser</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nadav0077?type=user' style='color: #4aa3ff;' target='new'> <strong> Nadav Magier</strong></a> was disclosed at July 31, 2026, 3:27 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>HTTP Request Smuggling</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Node.js HTTP server where it ignores the "Connection: close" header when the token is followed by a tab character. This allows an attacker to send a second request on the same connection, even after the first request should have closed the connection. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/mkepvaoi246x9gzrqwg0kagw6pqb/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3644182' style='color: #4aa3ff;' target='new'>Stored XSS in nameserver field on account settings page</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/axolot23?type=user' style='color: #4aa3ff;' target='new'> <strong> Axolot</strong></a> was disclosed at July 31, 2026, 3:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stored XSS vulnerability was discovered in the nameserver field on the account settings page. The lack of input validation and weak CSP configuration allowed the injection of malicious JavaScript code that executed when the settings page was reloaded. The vulnerability was limited to a self-XSS scenario, affecting only the account owner who injected the payload and not other users. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-30]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-30</link>
			<pubDate>Fri, 31 Jul 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-30</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/variants/qv48zkf423avl8lwrpzkjsh87o74/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542?response-content-disposition=inline%3B%20filename%3D%22176697.png%22%3B%20filename%2A%3DUTF-8%27%27176697.png&response-content-type=image%2Fpng&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQGK6FURQQ34SN3D7%2F20260731%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260731T070004Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJGMEQCICIXgypxx11R4nt1Ef3jLirYnREPZJQ2LpTRoLFt3y7YAiA56v0o5mW2zRP7EcnFEXWje2JUX8eVXXHtqxoYZjXShyq7BQim%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAMaDDAxMzYxOTI3NDg0OSIMFcpl9cKBPPGqSWsfKo8FWOpJ7hdwMJbf0Lp0UvEWaHrvz98CwWPlgCmx%2BlTeGa9UYH%2FP5WWNn%2B39PYJoootYk6HTqNIUa%2FiKDsYQGA%2FlBxxVahhD%2FI7oP5Cb8P3%2F8lwK81LafbhrOQSIKvl7WGRppUT%2B3j2XlRDIvQnnUjM%2Fv53URJrRSsu4hmw44vecAo1lzvo49g86Bj6nkQOyjAHoeYvLVx2KH91rjz8j8IZ3lbYzFuNnsBQttkJYZMDKHPwOeVioYtjHhqViZqNXvE69Liit4%2FT5q9Icj6XI1%2FBwr6mCfOgwyjwG7X1fT27wpTQulwWuTGZzfvlVKtu4h2mGFdZZgascJK6M4SwYGpfIEUFNRh%2F53oLZckN7EIhaaxcXHAPqLZZcWVWVEQtK0oJqPiJgi8L51fNxVivJf3zFRExjN1ZVCp%2FbZNEYVdsTVXq2mKGL4h4lepuuIDUdLRJ75lw1wiW3Nyv2XLe8wSYzAV%2FFpDTqVZ56picAMwG%2F2sT6Ik0H43zbERL8YUqk9qG4WW7Dkt11%2FgVmrOaz8HfBTsIjQUOyIdIeP0O94AGMJdDDEn0boE5jBM51fD7%2BdTtUGL59K1KNXlJF1nbZi1TfdAaK6H9uyc4tZbfs03%2FDCb36qo2k6%2B5gXrgzDMw7beIb%2FjUFysPO45cJIQUXCFaZFBfUxi9M5yRrN4PIdqvPBHTydyomChRCB0vyueeZhMYQpmtpG8o3AZYTuo%2BR21oUZ%2BHn%2FNuyTEGwd3D1CSS3VztK8PGqM6xHpIuYlTR3QGzPjVyUzCCFwmXVbSWpo3avUDgJ0STJ%2BcKKcWxkj8lFs6qcUfKIqgAoeNPzPbjd88dy1vR3EAwg%2BSY7aCFrBW%2FX%2BkBViArrx%2FsmKqfsGMuvizDe4bDTBjqyAX7Jko5yBfionHhGimuWdrV0akkvF8vqi27raieWBxvUdkdzBmIuFmfWLDtQd7GonlhwSPGmIs59MLa9SSy%2BwC8U6ipF3a6U4JCkRKN3I9dUWR6C5VfqRMTeICrKJPXNgh0kQN%2FhrPGFBtSdYtgdSTb0eiZ1dLabIPLlV0QIvGbC0HeOuD7i59h9oAH1BnrXNSJUpfa1%2FT5bHKmQdHaJIdtbcfXEXHqpAqsna%2F7k0wj5KaU%3D&X-Amz-SignedHeaders=host&X-Amz-Signature=d47d3d317189c939eae9402519cd5d5f027a84bd55302bd40e84643e87c5cdf9' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3606773' style='color: #4aa3ff;' target='new'>Stored XSS via SVG Upload — check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/a7mmr?type=user' style='color: #4aa3ff;' target='new'> <strong> Ammar Y. Sami</strong></a> was disclosed at July 30, 2026, 8:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stored XSS vulnerability was discovered in phpBB 4.0.0-a2-dev. The vulnerability was caused by an incomplete blocklist for file uploads and a 256-byte read limit in the content scanning check. Specifically, SVG files with malicious payloads in the onload and onbegin attributes were able to bypass the content check and be stored on the server. Additionally, any content beyond the 256-byte limit was not scanned, allowing payloads like &lt;script&gt; tags to be successfully uploaded. The uploaded SVG files were served with inline content disposition, causing the browser to render and execute the embedded JavaScript when the attachment link was clicked. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3815767' style='color: #4aa3ff;' target='new'>Permission Model bypass: process.report writes (and overwrites) files outside --allow-fs-write paths</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sinan-polat?type=user' style='color: #4aa3ff;' target='new'> <strong> Sinan Polat</strong></a> was disclosed at July 30, 2026, 3:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was found in the Node.js Permission Model enforcement that allowed the process.report function to write (and overwrite) files outside the --allow-fs-write paths. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3812439' style='color: #4aa3ff;' target='new'>HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vnyuh?type=user' style='color: #4aa3ff;' target='new'> <strong> vnyuh</strong></a> was disclosed at July 30, 2026, 2:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Exploiting Incorrectly Configured SSL/TLS</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/variants/qv48zkf423avl8lwrpzkjsh87o74/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542?response-content-disposition=inline%3B%20filename%3D%22176697.png%22%3B%20filename%2A%3DUTF-8%27%27176697.png&response-content-type=image%2Fpng&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQGK6FURQQ34SN3D7%2F20260731%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260731T070004Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJGMEQCICIXgypxx11R4nt1Ef3jLirYnREPZJQ2LpTRoLFt3y7YAiA56v0o5mW2zRP7EcnFEXWje2JUX8eVXXHtqxoYZjXShyq7BQim%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAMaDDAxMzYxOTI3NDg0OSIMFcpl9cKBPPGqSWsfKo8FWOpJ7hdwMJbf0Lp0UvEWaHrvz98CwWPlgCmx%2BlTeGa9UYH%2FP5WWNn%2B39PYJoootYk6HTqNIUa%2FiKDsYQGA%2FlBxxVahhD%2FI7oP5Cb8P3%2F8lwK81LafbhrOQSIKvl7WGRppUT%2B3j2XlRDIvQnnUjM%2Fv53URJrRSsu4hmw44vecAo1lzvo49g86Bj6nkQOyjAHoeYvLVx2KH91rjz8j8IZ3lbYzFuNnsBQttkJYZMDKHPwOeVioYtjHhqViZqNXvE69Liit4%2FT5q9Icj6XI1%2FBwr6mCfOgwyjwG7X1fT27wpTQulwWuTGZzfvlVKtu4h2mGFdZZgascJK6M4SwYGpfIEUFNRh%2F53oLZckN7EIhaaxcXHAPqLZZcWVWVEQtK0oJqPiJgi8L51fNxVivJf3zFRExjN1ZVCp%2FbZNEYVdsTVXq2mKGL4h4lepuuIDUdLRJ75lw1wiW3Nyv2XLe8wSYzAV%2FFpDTqVZ56picAMwG%2F2sT6Ik0H43zbERL8YUqk9qG4WW7Dkt11%2FgVmrOaz8HfBTsIjQUOyIdIeP0O94AGMJdDDEn0boE5jBM51fD7%2BdTtUGL59K1KNXlJF1nbZi1TfdAaK6H9uyc4tZbfs03%2FDCb36qo2k6%2B5gXrgzDMw7beIb%2FjUFysPO45cJIQUXCFaZFBfUxi9M5yRrN4PIdqvPBHTydyomChRCB0vyueeZhMYQpmtpG8o3AZYTuo%2BR21oUZ%2BHn%2FNuyTEGwd3D1CSS3VztK8PGqM6xHpIuYlTR3QGzPjVyUzCCFwmXVbSWpo3avUDgJ0STJ%2BcKKcWxkj8lFs6qcUfKIqgAoeNPzPbjd88dy1vR3EAwg%2BSY7aCFrBW%2FX%2BkBViArrx%2FsmKqfsGMuvizDe4bDTBjqyAX7Jko5yBfionHhGimuWdrV0akkvF8vqi27raieWBxvUdkdzBmIuFmfWLDtQd7GonlhwSPGmIs59MLa9SSy%2BwC8U6ipF3a6U4JCkRKN3I9dUWR6C5VfqRMTeICrKJPXNgh0kQN%2FhrPGFBtSdYtgdSTb0eiZ1dLabIPLlV0QIvGbC0HeOuD7i59h9oAH1BnrXNSJUpfa1%2FT5bHKmQdHaJIdtbcfXEXHqpAqsna%2F7k0wj5KaU%3D&X-Amz-SignedHeaders=host&X-Amz-Signature=d47d3d317189c939eae9402519cd5d5f027a84bd55302bd40e84643e87c5cdf9' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3606773' style='color: #4aa3ff;' target='new'>Stored XSS via SVG Upload — check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/a7mmr?type=user' style='color: #4aa3ff;' target='new'> <strong> Ammar Y. Sami</strong></a> was disclosed at July 30, 2026, 8:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stored XSS vulnerability was discovered in phpBB 4.0.0-a2-dev. The vulnerability was caused by an incomplete blocklist for file uploads and a 256-byte read limit in the content scanning check. Specifically, SVG files with malicious payloads in the onload and onbegin attributes were able to bypass the content check and be stored on the server. Additionally, any content beyond the 256-byte limit was not scanned, allowing payloads like &lt;script&gt; tags to be successfully uploaded. The uploaded SVG files were served with inline content disposition, causing the browser to render and execute the embedded JavaScript when the attachment link was clicked. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3815767' style='color: #4aa3ff;' target='new'>Permission Model bypass: process.report writes (and overwrites) files outside --allow-fs-write paths</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sinan-polat?type=user' style='color: #4aa3ff;' target='new'> <strong> Sinan Polat</strong></a> was disclosed at July 30, 2026, 3:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was found in the Node.js Permission Model enforcement that allowed the process.report function to write (and overwrite) files outside the --allow-fs-write paths. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3812439' style='color: #4aa3ff;' target='new'>HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vnyuh?type=user' style='color: #4aa3ff;' target='new'> <strong> vnyuh</strong></a> was disclosed at July 30, 2026, 2:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Exploiting Incorrectly Configured SSL/TLS</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-29]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-29</link>
			<pubDate>Thu, 30 Jul 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-29</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3812439' style='color: #4aa3ff;' target='new'>HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vnyuh?type=user' style='color: #4aa3ff;' target='new'> <strong> vnyuh</strong></a> was disclosed at July 30, 2026, 2:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Exploiting Incorrectly Configured SSL/TLS</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3638909' style='color: #4aa3ff;' target='new'>GitHub scoped user to server tokens can escape their installation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 29, 2026, 11:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3761342' style='color: #4aa3ff;' target='new'>Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sy2n0?type=user' style='color: #4aa3ff;' target='new'> <strong> Jiyong Yang</strong></a> was disclosed at July 29, 2026, 11:00 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3577216' style='color: #4aa3ff;' target='new'>`exportReportPdf` mutation shows internal Activity</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0v3rw4tch?type=user' style='color: #4aa3ff;' target='new'> <strong> kimingi</strong></a> was disclosed at July 29, 2026, 3:01 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue was promptly fixed by enforcing the same per-activity visibility checks and disclosure-level scoping along the export path. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3816840' style='color: #4aa3ff;' target='new'>HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yottt?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at July 29, 2026, 2:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3838601' style='color: #4aa3ff;' target='new'>Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0xoroot?type=user' style='color: #4aa3ff;' target='new'> <strong> Sir bugs</strong></a> was disclosed at July 29, 2026, 2:16 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3473145' style='color: #4aa3ff;' target='new'>Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at July 29, 2026, 1:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3812439' style='color: #4aa3ff;' target='new'>HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vnyuh?type=user' style='color: #4aa3ff;' target='new'> <strong> vnyuh</strong></a> was disclosed at July 30, 2026, 2:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Exploiting Incorrectly Configured SSL/TLS</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3638909' style='color: #4aa3ff;' target='new'>GitHub scoped user to server tokens can escape their installation</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 29, 2026, 11:35 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3761342' style='color: #4aa3ff;' target='new'>Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/sy2n0?type=user' style='color: #4aa3ff;' target='new'> <strong> Jiyong Yang</strong></a> was disclosed at July 29, 2026, 11:00 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3577216' style='color: #4aa3ff;' target='new'>`exportReportPdf` mutation shows internal Activity</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0v3rw4tch?type=user' style='color: #4aa3ff;' target='new'> <strong> kimingi</strong></a> was disclosed at July 29, 2026, 3:01 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue was promptly fixed by enforcing the same per-activity visibility checks and disclosure-level scoping along the export path. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3816840' style='color: #4aa3ff;' target='new'>HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yottt?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at July 29, 2026, 2:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/022/984/e600648ace4a8553247bce967d461a030aa81d49_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3838601' style='color: #4aa3ff;' target='new'>Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0xoroot?type=user' style='color: #4aa3ff;' target='new'> <strong> Sir bugs</strong></a> was disclosed at July 29, 2026, 2:16 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3473145' style='color: #4aa3ff;' target='new'>Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at July 29, 2026, 1:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-28]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-28</link>
			<pubDate>Wed, 29 Jul 2026 07:00:07 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-28</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3473145' style='color: #4aa3ff;' target='new'>Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at July 29, 2026, 1:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3633146' style='color: #4aa3ff;' target='new'>Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mistercloudsec?type=user' style='color: #4aa3ff;' target='new'> <strong> Sergio Garcia</strong></a> was disclosed at July 28, 2026, 3:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Certificate Validation</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was found in the Bedrock AgentCore Code Interpreter sandbox. The sandbox granted a user passwordless sudo access to a script that deployed certificates to the OS trust store. An attacker could have generated a rogue CA certificate, placed it in a writable directory, and then used the sudo-allowed script to inject the rogue CA into the trust store. This could have been used to perform man-in-the-middle attacks against TLS connections from the sandbox. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3473145' style='color: #4aa3ff;' target='new'>Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/button142857?type=user' style='color: #4aa3ff;' target='new'> <strong> KT</strong></a> was disclosed at July 29, 2026, 1:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3633146' style='color: #4aa3ff;' target='new'>Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mistercloudsec?type=user' style='color: #4aa3ff;' target='new'> <strong> Sergio Garcia</strong></a> was disclosed at July 28, 2026, 3:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Certificate Validation</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was found in the Bedrock AgentCore Code Interpreter sandbox. The sandbox granted a user passwordless sudo access to a script that deployed certificates to the OS trust store. An attacker could have generated a rogue CA certificate, placed it in a writable directory, and then used the sudo-allowed script to inject the rogue CA into the trust store. This could have been used to perform man-in-the-middle attacks against TLS connections from the sandbox. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-27]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-27</link>
			<pubDate>Tue, 28 Jul 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-27</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3775702' style='color: #4aa3ff;' target='new'>Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nick_frichette_dd?type=user' style='color: #4aa3ff;' target='new'> <strong> Nick Frichette (Datadog)</strong></a> was disclosed at July 27, 2026, 7:51 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insufficient Logging</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Amazon CloudWatch service, where certain non-production API endpoints could be used to perform permission enumeration without generating corresponding CloudTrail events. This allowed for silent testing of compromised IAM credentials. The vulnerability was reported to AWS, which acknowledged it as a security issue. Specific endpoints and operations that exhibited this behavior were identified and described in the report. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3827674' style='color: #4aa3ff;' target='new'>Authentication Bypass via XML Signature Wrapping in SAML SSO</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0jayden?type=user' style='color: #4aa3ff;' target='new'> <strong> jayden</strong></a> was disclosed at July 27, 2026, 4:37 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3775702' style='color: #4aa3ff;' target='new'>Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nick_frichette_dd?type=user' style='color: #4aa3ff;' target='new'> <strong> Nick Frichette (Datadog)</strong></a> was disclosed at July 27, 2026, 7:51 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insufficient Logging</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Amazon CloudWatch service, where certain non-production API endpoints could be used to perform permission enumeration without generating corresponding CloudTrail events. This allowed for silent testing of compromised IAM credentials. The vulnerability was reported to AWS, which acknowledged it as a security issue. Specific endpoints and operations that exhibited this behavior were identified and described in the report. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/858/ada6c92a338715afad123af214dd6e22fd8dc6ff_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3827674' style='color: #4aa3ff;' target='new'>Authentication Bypass via XML Signature Wrapping in SAML SSO</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0jayden?type=user' style='color: #4aa3ff;' target='new'> <strong> jayden</strong></a> was disclosed at July 27, 2026, 4:37 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-24]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-24</link>
			<pubDate>Sat, 25 Jul 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-24</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3621606' style='color: #4aa3ff;' target='new'>ZMQ RPC Log Injection and Untrusted Payload Persistence</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/redlobsterzzz?type=user' style='color: #4aa3ff;' target='new'> <strong> redlobsterz</strong></a> was disclosed at July 24, 2026, 7:19 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>CRLF Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as the master branch as of the reported date. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3621606' style='color: #4aa3ff;' target='new'>ZMQ RPC Log Injection and Untrusted Payload Persistence</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/redlobsterzzz?type=user' style='color: #4aa3ff;' target='new'> <strong> redlobsterz</strong></a> was disclosed at July 24, 2026, 7:19 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>CRLF Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as the master branch as of the reported date. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-22]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-22</link>
			<pubDate>Thu, 23 Jul 2026 07:00:07 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-22</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3809407' style='color: #4aa3ff;' target='new'>AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/notnotnotveg?type=user' style='color: #4aa3ff;' target='new'> <strong> notnotnotveg</strong></a> was disclosed at July 22, 2026, 7:53 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3641229' style='color: #4aa3ff;' target='new'>GitHub user to server tokens can create issues in any public repository</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 22, 2026, 7:39 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access to that repository. This vulnerability was fixed by adding a repository scope check for user-to-server tokens issued by global apps. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/3y22a5r49ryw4d4454msmh3frrgn/8f5393bb06e000811ac3ac31f77f5ce1d049785766c3d25a25cec97adaa9cc12' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3800870' style='color: #4aa3ff;' target='new'>connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kyotozzx?type=user' style='color: #4aa3ff;' target='new'> <strong> Kauã Ferreira</strong></a> was disclosed at July 22, 2026, 4:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Verification of Cryptographic Signature</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3809407' style='color: #4aa3ff;' target='new'>AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/notnotnotveg?type=user' style='color: #4aa3ff;' target='new'> <strong> notnotnotveg</strong></a> was disclosed at July 22, 2026, 7:53 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3641229' style='color: #4aa3ff;' target='new'>GitHub user to server tokens can create issues in any public repository</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 22, 2026, 7:39 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access to that repository. This vulnerability was fixed by adding a repository scope check for user-to-server tokens issued by global apps. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/3y22a5r49ryw4d4454msmh3frrgn/8f5393bb06e000811ac3ac31f77f5ce1d049785766c3d25a25cec97adaa9cc12' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3800870' style='color: #4aa3ff;' target='new'>connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kyotozzx?type=user' style='color: #4aa3ff;' target='new'> <strong> Kauã Ferreira</strong></a> was disclosed at July 22, 2026, 4:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Verification of Cryptographic Signature</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-21]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-21</link>
			<pubDate>Wed, 22 Jul 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-21</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/3y22a5r49ryw4d4454msmh3frrgn/8f5393bb06e000811ac3ac31f77f5ce1d049785766c3d25a25cec97adaa9cc12' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3800870' style='color: #4aa3ff;' target='new'>connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kyotozzx?type=user' style='color: #4aa3ff;' target='new'> <strong> Kauã Ferreira</strong></a> was disclosed at July 22, 2026, 4:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Verification of Cryptographic Signature</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3588801' style='color: #4aa3ff;' target='new'>OAuth redirect uri validation bypass for :proxima_first_party_sync apps</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 21, 2026, 9:43 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Open Redirect</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. The vulnerability was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. The vulnerability was reported through the GitHub Bug Bounty program. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/3y22a5r49ryw4d4454msmh3frrgn/8f5393bb06e000811ac3ac31f77f5ce1d049785766c3d25a25cec97adaa9cc12' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3800870' style='color: #4aa3ff;' target='new'>connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kyotozzx?type=user' style='color: #4aa3ff;' target='new'> <strong> Kauã Ferreira</strong></a> was disclosed at July 22, 2026, 4:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Verification of Cryptographic Signature</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/894/1de36b69ee85cb77397b0ee01ddbabd7ed47a3dd_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3588801' style='color: #4aa3ff;' target='new'>OAuth redirect uri validation bypass for :proxima_first_party_sync apps</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ahacker1?type=user' style='color: #4aa3ff;' target='new'> <strong> ahacker1</strong></a> was disclosed at July 21, 2026, 9:43 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Open Redirect</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. The vulnerability was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. The vulnerability was reported through the GitHub Bug Bounty program. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-20]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-20</link>
			<pubDate>Tue, 21 Jul 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-20</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3738727' style='color: #4aa3ff;' target='new'>Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/int0ha_?type=user' style='color: #4aa3ff;' target='new'> <strong> Connor Carro</strong></a> was disclosed at July 20, 2026, 12:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3738727' style='color: #4aa3ff;' target='new'>Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/int0ha_?type=user' style='color: #4aa3ff;' target='new'> <strong> Connor Carro</strong></a> was disclosed at July 20, 2026, 12:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-07-19]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-19</link>
			<pubDate>Mon, 20 Jul 2026 07:00:05 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-07-19</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3738727' style='color: #4aa3ff;' target='new'>Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/int0ha_?type=user' style='color: #4aa3ff;' target='new'> <strong> Connor Carro</strong></a> was disclosed at July 20, 2026, 12:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3738727' style='color: #4aa3ff;' target='new'>Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/int0ha_?type=user' style='color: #4aa3ff;' target='new'> <strong> Connor Carro</strong></a> was disclosed at July 20, 2026, 12:15 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted. </p>
              </div><br>]]></content:encoded>
		</item>
	</channel>
</rss>