一位创业者发现Y Combinator的Paxel应用存在严重安全漏洞,该应用用于评估创业学校申请者的代码质量 [1]。该漏洞源于缺少HMAC签名验证,允许任何人伪造并篡改上传到YC排名数据库的评分 [1]。
目前已有超过120万名开发者将报告上传到YC服务器 [1]。作者公开披露漏洞后,创建了paxel-boosted工具,在几小时内有20多名用户成功将自己的排名篡改为YC数据库中的全球前1% [1]。
作者在公开披露前曾提前12天通过私密邮件向YC报告该漏洞,但未获得回应 [1]。YC创始人Jared Friedman在作者公开披露后数小时内做出回应,并发布了补丁 [1]。该补丁涉及两项密码学修复:将LLM响应字段纳入HMAC计算,以及对敏感字段进行可选加密 [1]。
作为回应,YC邀请这位发现漏洞的作者参加今年的Startup School [1]。
A developer discovered a critical vulnerability in Y Combinator's Paxel application, a tool designed to evaluate the code quality of Startup School applicants, and publicly disclosed the flaw after receiving no response to a private report. [1]
The vulnerability stemmed from missing HMAC signature verification in the application, allowing anyone to forge and manipulate scores uploaded to YC's ranking database. [1] Paxel had accumulated over 1.2 million developer reports uploaded to YC servers at the time of disclosure. [1]
Following the public disclosure, the developer created a proof-of-concept tool called paxel-boosted, which enabled more than 20 users to rank themselves in the top 1% globally in YC's database within hours. [1] YC co-founder Jared Friedman responded within hours of the disclosure, releasing a patch and inviting the researcher to attend this year's Startup School. [1]
The developer had initially attempted responsible disclosure by privately notifying YC 12 days before going public, but received no response. [1] YC's remediation involved two cryptographic fixes: incorporating LLM response fields into HMAC calculations and implementing optional encryption for sensitive fields. [1]