flawme

Security Research

A collection of high-impact vulnerability research and disclosures.

Sarvam AI
High

Sarvam-105B Security Assessment: Identity Fragility

LLM Security

Disclosed a vulnerability chain where standard API usage patterns caused the Sarvam-105B model to revert to competitor identities, alongside a side-channel reasoning leak.

Unico IDtech
Critical

Critical Liveness Bypass & Admin Takeover

Auth Bypass

Discovered a critical vulnerability chain allowing unauthenticated bypass of biometric liveness detection and moderator takeover of private video conference rooms.

CLEAR
High

Administrative Identity Flow & 2FA Bypass Chain

2FA Bypass

Exploited a breakdown in environment isolation to bypass 2FA via a hardcoded staging secret, enabling extraction of unmasked Highly Sensitive PII.

Neon
High

Non-Superuser Access to pg_shadow Password Hashes

Info Disclosure

Found an issue where any authenticated database user could extract SCRAM-SHA-256 password hashes for all users and map complete internal infrastructure.

Embark Studios
High

Mass Information Disclosure of 10,000+ Internal Player Records

Data Exposure

Disclosed a Next.js data over-exposure vulnerability leading to the mass leakage of internal player records.

Braze, Inc.
High

Missing Authorization on Mass Email Subscription Manipulation

Missing Auth

Identified an endpoint allowing valid API keys to change email subscription states for arbitrary emails globally at ~2,500 addresses/second.

Ping Identity
Medium

CORS Misconfiguration Allows Cross-Origin Data Theft

CORS Bypass

Identified a misconfiguration on the PingOne API where the origin header is reflected with credentials enabled, allowing authenticated cross-origin data exfiltration.

Flipkart
High

Unauthenticated Access to Internal Service Registry

Info Disclosure

Discovered a public endpoint exposing the entire Myntra API infrastructure, including microservice names, team IDs, and historical SSRF/XSS payloads.

Coupang Taiwan
High

Unauthenticated Data Exfiltration via Salesforce Aura

IDOR

Leveraged a misconfigured Salesforce Community guest profile to access the Aura controller, exposing internal employee records and files.

Water-Link
High

Critical Information Disclosure via WAF Bypass

Info Disclosure

Reported an exposed developer file (info.aspx) accessible via a WAF bypass technique.

Libelle
High

Unauthenticated Sanity.io API Access Leaking Config

Info Disclosure

Found unprotected access to Sanity.io APIs that leaked internal architecture details and configuration files.

Exoscale
Medium

Widespread Information Disclosure via SOS Buckets

Data Exposure

Identified over 100 publicly listable SOS buckets containing sensitive resources across the bug bounty scope.

Syfe
Medium

Potential AWS S3 Bucket Takeover via JS Bundle

Bucket Takeover

Found an unregistered AWS S3 bucket explicitly referenced in the UAT application's JavaScript bundle, exposing it to hijacking.