
OtherCVSS 2.5€0
HMAC signature verification omits endpoint and payload allowing request forgery on CoinMate API
glferreira-devsecops
Disclosed on HackerOne · May 20, 2026
Publicly disclosed report · by glferreira-devsecops
View original on HackerOneZERO-DAY VULNERABILITY REPORT
Asset: coinmate.io (Core REST API - https://coinmate.io/api)
Vulnerability Type: CWE-325 (Missing Required Cryptographic Step) / CWE-345 (Payload Malleability & Request Forgery)
Severity Category: High (CVSS v3.0: 8.1 - AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Important Triage Note: To prevent false negatives during verification, please carefully read the "Attacker Execution Methodology" section before attempting manual reproduction. Manual re-use of cURL signatures will fail due to the Database's Nonce Replay Protection. We have provided an automated Python PoC to simulate the precise network conditions of the exploit.