← Beehiiv

2024 Beehiiv — Paywall bypass and JWT token leak

2024 Unknown records affected Share on X

Data compromised

Potential: paywall circumvention; user impersonation via JWT

Technical writeup

Security researcher discovered paywall bypass vulnerability and JWT token leak allowing user impersonation. Reported via bug bounty; both issues fixed. No evidence of exploitation.

Root cause

API design flaw; JWT exposure in client-server exchange

References