$7,500 Bug: Exposing Any HackerOne User’s Email via Private Program Invite
安全研究员发现HackerOne私人邀请系统存在漏洞,通过结合GraphQL查询和“邀请用户名”功能可泄露用户私人邮箱地址。该漏洞可能导致大规模隐私泄露、账户去匿名化及钓鱼攻击等风险。 2025-6-7 05:47:43 Author: infosecwriteups.com(查看原文) 阅读量:14 收藏

How One GraphQL Query Turned Private Invites into Public Data Leaks

Monika sharma

Summary

Security researcher haxta4ok00 uncovered a critical email disclosure vulnerability in HackerOne’s private program invitation system. By combining the “invite via username” feature with GraphQL queries, the researcher was able to leak any invited user’s private email address — without their consent or interaction.

This flaw, if exploited at scale, could have led to massive privacy violations, enabling attackers to de-anonymize HackerOne accounts, target users with phishing, or scrape thousands of emails from the platform.

Steps to Reproduce

  1. Navigate to a Customer’s Private Program Launch Page

Example: https://hackerone.com/hackerone_h1p_bbp3/launch

2. Invite a Known Username

  • Use the “Invite via Username” field
  • Enter a valid HackerOne username (e.g., zebra)
  • Submit the invite

3. Retrieve the Invite Token

  • After submission, the backend creates a token tied to that invite
  • Use the GraphQL query to extract…

文章来源: https://infosecwriteups.com/7-500-bug-exposing-any-hackerone-users-email-via-private-program-invite-de6fd6b3b6c8?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh