
HackerOne Bug Bounty Disclosure: node-run-posix-positional-argument-escaping-allows-shell-command-injection-yottt - RedPacket Security
CompanyNode.js
RedPacket Security
HackerOne Bug Bounty Disclosure: taskcluster-web-server-oauth-authorization-codes-are-reusable-and-the-exchange-handler-checks-the-wrong-expiry-column-anshuman-bh - RedPacket Security
CompanyMozilla
RedPacket Security
HackerOne Bug Bounty Disclosure: -click-account-takeover-via-open-redirect-through-regex-bypass-in-domain-validation-farr - RedPacket Security
CompanyKhan Academy
RedPacket Security
HackerOne Bug Bounty Disclosure: reflected-xss-in-ai-chat-bot-greetings-at-help-shopify-com-via-markdown-image-rendering-saltymermaid - RedPacket Security
CompanyShopify
RedPacket Security
HackerOne Bug Bounty Disclosure: permission-model-bypass-via-process-report-writereport-path-misvalidation-suul - RedPacket Security
CompanyNode.js
RedPacket Security
HackerOne Bug Bounty Disclosure: http-sessions-never-clean-up-after-goaway-on-invalid-protocol-errors-pimterry - RedPacket Security
CompanyNode.js
RedPacket Security
HackerOne Bug Bounty Disclosure: authenticated-elasticsearch-painless-script-execution-via-query-search-sort-query-on-hackerone-com-graphql-brumbelow - RedPacket Security
CompanyHackerOne
RedPacket Security
HackerOne Bug Bounty Disclosure: verify-release-rebuilds-from-the-tarball-under-verification-enabling-pre-check-command-execution-and-false-ok-for-a-malicious-curl-release-tarball-argareksapatii - RedPacket Security
Companycurl
RedPacket Security
HackerOne Bug Bounty Disclosure: vulnerability-report-buffer-overflow-in-path-sanitization-newstuff - RedPacket Security
Companycurl
RedPacket Security
HackerOne Bug Bounty Disclosure: malicious-conflux-endpoint-can-leave-stale-global-ooo-queue-accounting-after-teardown-aptupdate - RedPacket Security
CompanyTor
RedPacket Security