Skip to content

program: Fanbase #471

@kellyclarksonn38

Description

@kellyclarksonn38

URL

No public security policy found.

Contact

https://www.fanbase.app/

Bounty

None

Additional Information

A critical security vulnerability has been identified in the API of fanbase.app. The API allows an attacker to send messages from multiple user accounts without proper authentication or authorization.

This suggests a failure to validate tokens or session ownership on message endpoints, which could lead to mass account impersonation and user privacy violations.

This issue was verified based on observed unauthorized messages being sent from various unrelated accounts to a single target user. For ethical and safety reasons, I am not including user data or screenshots.

I prefer to remain anonymous due to safety concerns but am reporting this issue to prevent further abuse.

This vulnerability could result in:

  • Identity impersonation
  • Harassment using other users' accounts
  • Reputational damage
  • Potential regulatory or platform takedowns (App Store, Play Store)

Fanbase should urgently review their backend API authentication and permission checks, particularly on all messaging-related endpoints.

Thank you for helping to escalate this responsibly.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions