I reported a bug that could cause millions in losses for Vercel. However, they assigned someone to evaluate my report who didn’t understand anything I said and ultimately claimed it was normal. I would like to know if I can post on Twitter how to do this, since it’s normal and you’re assuming the loss. I only asked for a reward for discovering and reporting it; you need to improve the quality of critical analysis by your employees who review bug reports. The employee kept asking me for HTTP requests, and I was informing them that exploiting the bug didn’t require HTTP requests.}
Do you have a link to this? Was this in the community platform, or elsewhere?
It was on HackerOne.
Can you share a link?
Como adquirir um?
The link to the HackerOne post ![]()
The thread on HackerOne is private; I can’t share it. I can only take screenshots.
Can’t you create a channel so I can show you how to share it, instead of here in the post where anyone can see it?