~/disclosures

Coordinated disclosures.

Findings from real research, published responsibly. Details are withheld until vendors have had time to remediate — these writeups focus on root cause, impact and lessons, not exploits.

4 disclosures · 4 categories · redacted by default

High 1Medium 3# responsible-disclosure

Disclosure policy

Every finding here follows a coordinated disclosure process. Technical specifics — endpoints, parameters, tokens, and reproduction steps — are intentionally omitted while remediation is in progress. If you operate an affected service and need the full report, reach out through the published security channel.

HighCWE-287Improper Authentication

Kaltura — Email Verification Bypass in Self-Serve Signup

Kaltura's self-serve signup issued live, authenticated partner accounts without ever verifying the email — an unvalidated CAPTCHA, a verification secret returned in the API response, and a login path that never checked verification status at all.

redacted
read →
MediumCWE-306Broken Authentication

Vercel — OAuth Token Introspection Without Caller Authentication

Vercel's OAuth 2.0 introspection endpoint returned full token claims to any caller, with no client authentication and no rate limiting. The sibling revocation endpoint enforced credentials — which is what turned this from a design choice into a wiring gap.

redacted
read →
MediumCWE-915Mass Assignment

NBA — Client-Controlled Subscription Identity Fields on a Profile Update Endpoint

An identity endpoint on NBA's consumer platform accepted writes to payment and subscription linkage identifiers that should never be client-controlled. A case study in incomplete allowlists and why one validated field is the loudest signal in the response.

redacted
read →
MediumCWE-940Improper Verification of Source

OPPO — Stealing a Verification Ticket via Unvalidated MessagePort Adoption

OPPO's step-up verification page on id.oppo.com could be framed by any origin and opened a MessageChannel to its parent without checking event.origin. The browser handed the authentication result to the attacker's frame instead of the legitimate one.

redacted
read →