The /reports/:id.json endpoint discloses potentially sensitive user attributes when reporter summary is present

Disclosed: 2025-04-01 18:23:00 By avinash_ To security
Critical
Vulnerability Details
Hi The.json endpoint of any disclosed report is leaking reporter's email, OTP backup codes, reporter's phone number, "graphql_secret_token", tshirt size all the reporter account's internal details etc. ``` GET /reports/█████.json HTTP/2 Host: hackerone.com ```` * I was checking Hackerone's disclosed report ██████████ and suddenly during check found .json point is leaking too much data of reporter ```████``` . I immediately reported it to you. █████ * PoC:- Leakage of data of reporter █████ █████ ## Impact Reporter H1 account private data disclosed
Actions
View on HackerOne
Report Stats
  • Report ID: 3000510
  • State: Closed
  • Substate: resolved
  • Upvotes: 20
Share this report