Security research, bug bounty writeups, and technical deep dives.
A file upload endpoint on an OpenAI platform accepted arbitrary content types, enabling stored XSS via malicious XML upload. Demonstrated cookie theft and session hijacking. $3,600 bounty.
Any board member can view, pull, attach, and remove another user's private third-party data through a Trello PowerUp. $1,200 bounty. Details redacted — unresolved.
Bypassing Trello's "Invite Only" workspace restriction through the Slack-Trello integration's joinTeam callback. Any Slack member can self-join a linked Trello workspace.
A normal workspace member can bypass all board deletion restrictions by moving the board to their own workspace via PUT request, then deleting it there.
Any board member can execute another user's private (Local) Butler automation board buttons via the powerup-run-command API. Card buttons are protected; board buttons aren't.
The lowest-privilege role can share automation libraries with the entire workspace by bypassing client-side restrictions. Duplicate finding, fixed.
Register with the victim's email, skip verification, wait for the victim to sign up via Google OAuth — both accounts merge. Duplicate finding, originally reported Aug 2020.