logo

DoorDash email spoofing vulnerability sparks messy disclosure dispute

ID: e33f03d8-1c75-5e45-980a-fef8dbb71858

STIX ID: report--e33f03d8-1c75-5e45-980a-fef8dbb71858

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-11-17

Date Updated: 2026-07-18

Author: Ax Sharma

...
...

A security researcher discovered a stored HTML injection in DoorDash for Business that allowed anyone to create employee entries and send fully branded DoorDash emails from [email protected], enabling highly convincing phishing messages; the issue was later patched after a prolonged disclosure dispute between the researcher and DoorDash that involved demands for payment and the researcher's removal from the bug bounty program, and the flaw did not expose customer data or internal systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.