Scam Alert: opensea.io — OpenSea – Unanswered XSS Vulnerability Report via Profile Picture Upload
Company / Program: opensea.io
Platform: Other · Severity: critical · Scam type: ignored
Published:
Reported by: thomasmitchell
In 2021, I reported a stored XSS vulnerability affecting the profile picture upload functionality on OpenSea. The issue allowed a malicious file to be uploaded and executed in a way that could potentially lead to JavaScript execution within the application context.
I responsibly disclosed the vulnerability through the appropriate channels and provided technical details required to reproduce the issue. However, I never received a response, acknowledgment, or bounty payment regarding the report.
The purpose of this submission is to document the disclosure attempt and the lack of follow-up from the affected platform.