Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026

FS#515 - No Rate Limit on /transfer/add/ — Invitation Spam Abuse (CVSS 5.3 Medium)

## Summary

POST /transfer/add/ (authenticated) has no rate limiting. Any free-tier user can spam transfer invitations to arbitrary email addresses, abusing alwaysdata's invitation email system for harassment.

Severity: Medium (CVSS 5.3) | CWE-307
CVSS: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

## Reproduce
1. Log in with any free account
2. Fire 30 concurrent POSTs to /transfer/add/ with email=victim@example.com 3. All 30 return HTTP 200 — no throttling triggered

## Evidence
- 30/30 HTTP 200 (parallel, ~1.55s total)
- No 429 even under concurrent load

## Impact
- Spam victim with unlimited alwaysdata-branded transfer invitation emails
- Abuse alwaysdata sending reputation for targeted harassment

## Remediation
Limit: 5-10 invitations/hour per user + 3/day per target email.

Researcher: adityahadipratama4@gmail.com Full PDF report (4 findings) attached via support ticket.

Closed by  cbay
05.10.2026 07:24
Reason for closing:  Invalid
Admin
cbay commented on 05.10.2026 07:23

Hello,

There is a rate limit, and even if there weren't, it's not a vulnerability anyway.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing