frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Suno.com security disclosure: JWT token leakage, IDOR, and DoS vulnerabilities

https://github.com/theelderemo/suno-security-disclosure
4•theelderemo•3h ago

Comments

theelderemo•3h ago
I'm publicly disclosing three high-severity vulnerabilities I discovered in the Suno.com web application on October 9, 2025, after the vendor failed to engage in a proper coordinated disclosure process.

The vulnerabilities are:

Finding 1: Excessive Data Exposure / JWT Token Leakage (High Severity): Critical API endpoints return active JWT session tokens directly in the JSON response body. This allows for session hijacking and account takeover by any malicious browser extension, completely bypassing MFA. Suno's response indicated a misunderstanding of client-side threats, claiming that since the client already has the token, it's not an issue.

Finding 2: Broken Object Level Authorization (IDOR) (High Severity): The API does not validate if a user owns a resource before returning data. This allows any authenticated user to access the private content of any other user, including private songs, prompts, and generation history, simply by enumerating user IDs.

Finding 3: Unrestricted Resource Consumption (DoS) (Medium Severity): A batch endpoint for retrieving songs has no server-side limits on the number of IDs that can be requested. This allows an attacker to trigger resource exhaustion and cause a denial of service.

I attempted to responsibly disclose these findings to Suno. They dismissed the first two findings and, most concerningly, suggested I transmit the full proof-of-concept details through a Google Form. After I rejected this insecure method and offered multiple secure alternatives to which they did not respond, I made the decision to publicly disclose to protect users.

For a full technical breakdown, including disclosure timeline, proof-of-concept code, and remediation guidance for both users and Suno, please see the full advisory

Trap the Critters with Paint

https://deepanwadhwa.github.io/freeze_trap/
1•deepanwadhwa•1m ago•0 comments

Psychogeography makes maps of our emotions–with impact on health

https://theconversation.com/psychogeography-makes-maps-of-our-emotions-with-huge-potential-for-he...
1•PaulHoule•1m ago•0 comments

Apple's Next CEO Identified

https://www.macrumors.com/2025/10/08/heres-who-is-expected-to-be-next-apple-ceo/
1•thelastgallon•3m ago•0 comments

pgtricks – two tools for backing up PostgreSQL database dumps

https://github.com/akaihola/pgtricks
1•gjvc•5m ago•0 comments

Show HN: Praxos – Webhooks for Your Life

3•mogusian•6m ago•2 comments

China Builds Replicas of Taiwanese Gov Buildings for Special Forces Training

https://militarnyi.com/en/news/china-builds-new-replicas-of-taiwanese-government-buildings-for-sp...
1•giuliomagnifico•6m ago•0 comments

An Immense Solar Project Just Got Canceled Under Trump

https://www.nytimes.com/2025/10/10/climate/nevada-solar-esmerelda7.html
1•breadwinner•10m ago•1 comments

Cloudflare Bankrolls Fascists

https://drewdevault.com/2025/09/24/2025-09-24-Cloudflare-and-fascists.html
3•spinningarrow•11m ago•1 comments

Google, Meta and Microsoft opts to stop showing political ads in EU

https://www.politico.eu/article/eu-political-ad-rules-google-meta-microsoft-big-tech-kick-in/
3•martinohansen•11m ago•0 comments

OpenAI subpoena'd various nonprofits to get them to shut up on SB 53

https://twitter.com/_NathanCalvin/status/1976649051396620514
1•LinchZhang•15m ago•1 comments

WTF Is the Synergic Mode?

https://malcolmocean.com/2025/10/wtf-is-the-synergic-mode/
1•tasshin•15m ago•0 comments

Should You Use Upper Bound Version Constraints?

https://iscinumpy.dev/post/bound-version-constraints/
2•birdculture•17m ago•0 comments

The Long Trail Back

https://angryweasel.substack.com/p/the-long-trail-back
1•mooreds•18m ago•0 comments

The A.I. Prompt That Could End the World

https://www.nytimes.com/2025/10/10/opinion/ai-destruction-technology-future.html
1•mooreds•20m ago•0 comments

In the age of algorithms, one Irish town still does love the old-fashioned way

https://text.npr.org/nx-s1-5563978
2•mooreds•20m ago•0 comments

The "Get Your Shit Together" Day

https://frantic.im/get-your-shit-together-day/
1•higgins•20m ago•0 comments

I Choose Email over Messaging

https://www.spinellis.gr/blog/20250926/
1•naves•20m ago•1 comments

Genes Have Harnessed Physics to Help Grow Living Things

https://www.quantamagazine.org/genes-have-harnessed-physics-to-help-grow-living-things-20251010/
3•pykello•23m ago•0 comments

A window into modern loan origination

https://www.bitsaboutmoney.com/archive/window-modern-loan-origination/
1•chollida1•23m ago•0 comments

Trusted Execution Environments? More Like "Trust Us, Bro" Environments

https://libroot.org/posts/trusted-execution-environments/
5•libroot•27m ago•1 comments

We're All Behind the Curve

https://www.transformernews.ai/p/were-all-behind-the-curve-ai-bubble-crash-risk
2•frozenseven•28m ago•0 comments

I struggle to find old messages in AI conversations

https://ai-answer-saver.vercel.app/
1•nemo30s•34m ago•1 comments

Ask HN: Where would AI save you the most time in your robotics workflow today?

1•Lazaruscv•35m ago•0 comments

What's that animal on the front of your O'Reilly book?

https://www.oreilly.com/animals.csp
2•uticus•35m ago•0 comments

Opensoundcontrol.org (2021)

https://opensoundcontrol.stanford.edu/index.html
1•turtleyacht•36m ago•0 comments

Show HN: Modeling the Human Body in Rust So I Can Cmd+Click Through It

https://github.com/lantos1618/open_human_ontology
12•lleong1618•36m ago•1 comments

Show HN: I built a SaaS in 8 weeks, solo, using our own AI platform

https://www.zine.ai/blog/how-i-built-zine-in-3-months-with-ai-coding
1•kirkmarple•37m ago•0 comments

Trying to Blog More Often

https://binarydigit.city/trying-to-blog-more-often/
2•speckx•39m ago•1 comments

Indian immigrant fights deportation; police mistake perfume 'Opium' for narcotic

https://www.nbcnews.com/news/asian-america/indian-immigrant-deportation-opium-perfume-bottle-rcna...
1•ceejayoz•39m ago•0 comments

AI receptionist that answers real phone calls

1•kaansarac•44m ago•3 comments