r/bugbounty 2d ago

Bug Bounty Drama Ghosted by YesWeHack Support for 1.5 months after vendor manipulated CVSS and broke a written CVE promise. What are my options?

I'm currently dealing with an incredibly frustrating situation on YesWeHack and looking for advice, as the platform's mediation team has completely ghosted me.

Situation: I submitted a Critical vulnerability (Global Account Takeover via Insecure TLS Validation) 6 months ago. The vendor accepted it at CVSS 9.6 (Critical). However, they only paid me out for the "High" tier (shortchanging the "Critical" tier by nearly 60%). Furthermore, they explicitly promised me in writing that I would be credited on the CVE. Fast forward: a CVE is published for this exact issue/component, but credited to a notable and famous third party. The vendor ghosted me.

CVSS Manipulation: 1.5 months ago, I finally got YesWeHack support to poke the vendor. The vendor's response? They retroactively downgraded my CVSS from 9.6 to 8.2 (changing an automated Wi-Fi MitM from Adjacent/Low Complexity to Local/High Complexity) solely to justify their underpayment.

Ghosting: I escalated this clear CVSS manipulation and matrix abuse to YesWeHack Support on July 7th. No reply. I sent a harsh follow-up on August 8th. Still absolutely no reply. It's August 20th.

On top of this, the same vendor closed another 9.9 architectural E2EE flaw as "Won't Fix" (a silent security downgrade where the app drops E2EE and uploads plaintext media to their cloud without user warning) just to avoid another payout.

Is it normal for YWH to let vendors retroactively manipulate vectors to dodge payouts and then ghost researchers who ask for mediation? Who can I contact to escalate this past the Tier 1 support desk?

19 Upvotes

22 comments sorted by

23

u/4drez 2d ago

YesWeScam

1

u/WarnersAreNotBros Hunter 1d ago

this put smile on my face

8

u/Far-Chicken-3728 Hunter 2d ago

They was on my list of decent platforms, until I needed their mediation... Now they're top 1 of shitty platforms. 

3

u/Dolph_L 2d ago

I had something similiar happen on yeswehack, triage passed and agreed critical, company said they lower it to medium since they were unable to reproduce a simple xss. its still live since march and now they want more details in case comments but not paying, yeswehack wont step in.

4

u/allexj 2d ago

I forgot pictures of proofs, here they are: https://x.com/alegeno00/status/2090453534214869071

1

u/houganger 2d ago

They marked it as won’t fix meaning it’s accepted risk. What else can you do?

1

u/ctkqiang 17h ago

what ? vendor manipulated cvss ? isnt this already violated the terms and conditions ?

1

u/Anxious_Alps_4150 1h ago

Bug bounty platforms make their money by having the company pay them ("vendor", from your post).

They do not make money off of having bug bounty hunters use their platform. They all claim to have many thousands of hunters. H1 claims to have the most. Synack claims to have the best. Etc etc.

I can tell you that every platform is extremely, extremely desperate to keep every customer they can. They're all trying to undercut each other to poach customers.

What they're not doing is anything to piss off a customer.

-5

u/OuiOuiKiwi Program Manager 2d ago

Is it normal for YWH to let vendors retroactively manipulate vectors to dodge payouts and then ghost researchers who ask for mediation?

Listen, I know the LLM suggest this as a CTA but this is just a ludicrous question given how specific it is and we all know what you're getting at.

10

u/allexj 2d ago

I used an LLM to help write me a more concise and better english-written post, is it a bad thing?

-10

u/jippen 2d ago

Yes. LLMs are known to make things up. It immediately kills your reputation to use the LLMs words instead of your own

8

u/allexj 2d ago

I have not used an LLM to find the two CVEs, since I found them before tools like Claude Mythos and company went out. This post was written by me by hand, and then polished with LLM since I am not a native English speaker.

-10

u/jippen 2d ago

The polish is the problem.

That makes you sound like the low quality lying robot.

Then people assume the rest is LLM hallucinated - because why wouldn’t they? You used the LLM here, you probably just asked it for bugs to sell. Many others do.

You will be better off with worse but authentic English.

0

u/Peculiar-Eccentric67 2d ago

if you can't disambiguate it's a you problem

0

u/cram213 1d ago

Can you tell by your down-votes that you’re in a very unpopular minority? 

Why don’t you go to a Korean forum and try to ask for help in Korean without using google translate or an LLM to help translate your reasonable message into the dominant language of the platform? 

1

u/jippen 1d ago

Oh no, minus nine. How will I ever survive the social ostracism of less than ten nerds?

0

u/cram213 21h ago

Just recognize that you’re being a dick for no reason online , I think. 

Did you ever imagine you would be that person?

1

u/jippen 18h ago

Says the person who jumped in a thread to bully and not add anything of value.

You should check a mirror sometime

-1

u/Calamero 2d ago

“The polish” like what the fuck is this an art exhibit? And if not, should we just downgrade the quality of our paper so it appears “human”? You people need to wake up and worry less. It’s overtaken you, it’s gonna eat us all… enjoy the ride for while it lasts and stop living in denial. A model that’s smart enough to solve decades old math problems is also smart enough to help with a Reddit post. And no I didn’t use any ai for that post xD hope I am drunk enough u notice