Security Report Follow-Up — Additional Critical Customer PII Exposure Identified

I wanted to follow up on a couple of security issues I recently discovered and reported through your internal channels.

I originally reported these issues on August 2 at 17:29 IST, directly to contacts within the company, including the CTO, CEO, and an employee email address.

One of the reports was submitted with the subject:

Unauthorized member addition to other projects, send legitimate invitation emails, and disclose project members’ PII — I found your project and members’ emails through this security issue.

Since then, I’ve identified another, potentially more critical security issue that appears to expose customer PII. I’m reaching out to report this responsibly and want to make sure it reaches the appropriate security or Development team as soon as possible.

I haven’t received a response or acknowledgement to my earlier reports, so I’m concerned they may have been missed or may not have reached the right team.

I’m intentionally not sharing any vulnerability details, customer information, or proof publicly. My goal is to give the company a reasonable opportunity to investigate and address these issues responsibly.

I’m happy to provide the technical details privately through the appropriate security channel and work with the team to help verify and resolve the issues.

Hopefully, this reaches the right people. I appreciate your time and look forward to working with the security team on this.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

About 1 hour ago

Author

Akhil

Subscribe to post

Get notified by email when there are changes.