BugCrowd Bug Bounty Disclosure: P2 – Graphql API exposes all groups and goups users leaking internal stucture, full names and emails – vinax

Graphql API exposes all groups and goups users leaking internal stucture, full names and emails

Graphql API exposes all groups and goups users leaking internal stucture, full names and emails

Researcher: vinax
Engagement: National Aeronautics and Space Administration (NASA) – Vulnerability Disclosure Program
Disclosed at: 2025-08-01T19:21:24Z
Priority: P2
Status: Resolved

Summary

A publicly accessible GraphQL API exposed sensitive group and user information to unauthenticated users. By leveraging the wildcard search feature in the tags parameter, an attacker could enumerate groups in bulk, leading to the exposure of PII.

Activity Feed

Actor Details Timestamp (UTC)
Martin_NASA Martin_NASA published 2025-08-01T19:21:24Z
vinax vinax requested 2025-08-01T15:33:48Z
vinax vinax sent a: message 2025-08-01T15:25:12Z
Medx Medx sent a: message 2025-08-01T15:20:52Z
Parker_Bugcrowd Parker_Bugcrowd changed the state to to resolved 2025-08-01T14:50:22Z
ZachFahoury ZachFahoury sent a: message 2025-07-31T17:56:26Z
Medx Medx sent a: message 2025-07-24T17:34:54Z
Martin_NASA Martin_NASA changed the state to to unresolved 2025-07-11T14:51:34Z
Mason357_Bugcrowd Mason357_Bugcrowd sent a: message 2025-07-10T17:43:59Z
Mason357_Bugcrowd Mason357_Bugcrowd changed the state to to triaged 2025-07-10T17:43:53Z
Mason357_Bugcrowd Mason357_Bugcrowd changed the severity to 2025-07-10T17:43:52Z
vinax vinax created the submission 2025-07-10T14:56:09Z

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.