Privilege escalation through a GraphQL authorization gap
A GraphQL authorization gap let a limited Program Admin join privileged groups and gain report and reward permissions.

Independent Security Researcher
I find security vulnerabilities, report them responsibly, and share what I learn.
A GraphQL authorization gap let a limited Program Admin join privileged groups and gain report and reward permissions.
A race condition in HackerOne’s 2FA recovery flow created multiple active reset requests, allowing one cancellation to leave others valid.
A repeatable workflow for understanding compact targets, exercising every endpoint, and finding product-logic flaws beyond basic reconnaissance.
Pre-authentication state and an organization-switch endpoint combined to bypass 2FA.
An email-change confirmation link updated whichever account opened it because the token was not bound to the account that requested the change.