api-playground

1 article
sort: new top best
clear filter
0 8/10

A researcher discovered an SSRF vulnerability in Vimeo's API Playground by chaining path traversal, HTTP redirects, and an open redirect to reach internal Google Cloud metadata endpoints, ultimately extracting service account tokens and demonstrating potential RCE capability through SSH key injection.

Vimeo Google Cloud André Baptista Brett Ben Harsh Jaiswal HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 8 hours ago · details