$7,500 Bug: Exposing Any HackerOne User’s Email via Private Program Invite
安全研究员haxta4ok00发现HackerOne私人项目邀请系统中的一个严重漏洞,通过结合GraphQL查询和“邀请用户名”功能,可泄露受邀用户的私人邮箱地址。此漏洞可能导致大规模隐私泄露和账户去匿名化风险。 2025-6-7 05:47:43 Author: infosecwriteups.com(查看原文) 阅读量:12 收藏

How One GraphQL Query Turned Private Invites into Public Data Leaks

Monika sharma

Summary

Security researcher haxta4ok00 uncovered a critical email disclosure vulnerability in HackerOne’s private program invitation system. By combining the “invite via username” feature with GraphQL queries, the researcher was able to leak any invited user’s private email address — without their consent or interaction.

This flaw, if exploited at scale, could have led to massive privacy violations, enabling attackers to de-anonymize HackerOne accounts, target users with phishing, or scrape thousands of emails from the platform.

Steps to Reproduce

  1. Navigate to a Customer’s Private Program Launch Page

Example: https://hackerone.com/hackerone_h1p_bbp3/launch

2. Invite a Known Username

  • Use the “Invite via Username” field
  • Enter a valid HackerOne username (e.g., zebra)
  • Submit the invite

3. Retrieve the Invite Token

  • After submission, the backend creates a token tied to that invite
  • Use the GraphQL query to extract…

文章来源: https://infosecwriteups.com/7-500-bug-exposing-any-hackerone-users-email-via-private-program-invite-de6fd6b3b6c8?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh