Researcher Finds Cloudflare Turnstile Token Bypass, Denied Bug Bounty Payout
A security researcher discovered that Cloudflare Turnstile CAPTCHA tokens can be copied from one browser and reused in another, effectively bypassing the verification system entirely. The bypass required no scripting and was performed manually, making it distinct from automated attack methods. When the researcher reported the flaw through Cloudflare's bug bounty program, the company declined to pay, citing a policy exclusion for automated bypasses. Cloudflare acknowledged the policy wording was vague and said it would be updated, but closed the report without compensation. The researcher noted that Cloudflare appeared to be fixing the vulnerability regardless, raising concerns about how bug bounty programs handle edge-case disclosures.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in