OpenAI

OpenAI — Insecure File Upload to Stored XSS & Session Hijacking

A file upload endpoint on an OpenAI platform accepted arbitrary content types, enabling stored XSS via malicious XML upload. Demonstrated cookie theft and session hijacking. $3,600 bounty.

Atlassian

Trello PowerUp Integration — Accessing Other Users' Private External Data

Any board member can view, pull, attach, and remove another user's private third-party data through a Trello PowerUp. $1,200 bounty. Details redacted — unresolved.

Atlassian

Trello Workspace Self-Join Bypass via Slack Integration

Bypassing Trello's "Invite Only" workspace restriction through the Slack-Trello integration's joinTeam callback. Any Slack member can self-join a linked Trello workspace.

Atlassian

Trello Board Deletion Bypass — Privilege Escalation via Board Move API

A normal workspace member can bypass all board deletion restrictions by moving the board to their own workspace via PUT request, then deleting it there.

Atlassian

Trello Butler — Executing Another User's Private Board Buttons

Any board member can execute another user's private (Local) Butler automation board buttons via the powerup-run-command API. Card buttons are protected; board buttons aren't.

Atlassian

Trello Butler — Board Observer Can Share Automation Rules With the Workspace

The lowest-privilege role can share automation libraries with the entire workspace by bypassing client-side restrictions. Duplicate finding, fixed.

Atlassian

Trello OAuth Pre-Account Takeover — Email Verification Bypass

Register with the victim's email, skip verification, wait for the victim to sign up via Google OAuth — both accounts merge. Duplicate finding, originally reported Aug 2020.