TOPROCKSTARGAMES.md

July 18, 2026 · View on GitHub

Top reports from Rockstar Games program at HackerOne:

  1. The return of the < to Rockstar Games - 569 upvotes, $1000
  2. Account Takeover using Linked Accounts due to lack of CSRF protection to Rockstar Games - 237 upvotes, $0
  3. Stealing Facebook OAuth Code Through Screenshot viewer to Rockstar Games - 200 upvotes, $0
  4. XSS STORED AT socialclub.rockstargames.com (add friend request from profile attacker) to Rockstar Games - 194 upvotes, $0
  5. xss on https://www.rockstargames.com/GTAOnline/jp/screens/ to Rockstar Games - 159 upvotes, $0
  6. Access to the business emails of Rockstar Support agents through the support platform to Rockstar Games - 148 upvotes, $550
  7. Unserialize leading to arbitrary PHP function invoke to Rockstar Games - 118 upvotes, $0
  8. Stored XSS in Snapmatic + R★Editor comments to Rockstar Games - 118 upvotes, $0
  9. SocialClub Account Take Over Through Import Friends feature to Rockstar Games - 116 upvotes, $0
  10. Referer Leakage Vulnerability in socialclub.rockstargames.com/crew/ leads to FB'S OAuth token theft. to Rockstar Games - 112 upvotes, $0
  11. CSRF Vulnerability on https://signin.rockstargames.com/tpa/facebook/link/ to Rockstar Games - 104 upvotes, $0
  12. Password and mail address stored unencrypted in memory - Rockstar Game Launcher to Rockstar Games - 88 upvotes, $750
  13. Open redirect vulnerability to Rockstar Games - 83 upvotes, $250
  14. Blind SSRF in emblem editor (2) to Rockstar Games - 81 upvotes, $1500
  15. LFI and SSRF via XXE in emblem editor to Rockstar Games - 79 upvotes, $1500
  16. Cache Poisoning DoS on updates.rockstargames.com to Rockstar Games - 77 upvotes, $0
  17. XSS on rockstargames.com to Rockstar Games - 74 upvotes, $500
  18. Facebook OAuth Code Theft through referer leakage on support.rockstargames.com to Rockstar Games - 71 upvotes, $0
  19. Insecure Direct Object Reference allows Crew Invite deletion to Rockstar Games - 66 upvotes, $0
  20. Unquoted Service Path in "Rockstar Game Library Service" to Rockstar Games - 60 upvotes, $0
  21. Social Club Account Takeover Via RGL And Steam/Epic Linked Account to Rockstar Games - 54 upvotes, $0
  22. Brute Force against VMware Horizon to Rockstar Games - 53 upvotes, $250
  23. SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE to Rockstar Games - 51 upvotes, $1500
  24. Improper Authentication inside the Rockstar Games Launcher which leads to Account takeover to some extend to Rockstar Games - 50 upvotes, $750
  25. Bypass CAPTCHA protection to Rockstar Games - 50 upvotes, $0
  26. Stored XSS on support.rockstargames.com to Rockstar Games - 49 upvotes, $1000
  27. full path disclosure on www.rockstargames.com via apache filename brute forcing to Rockstar Games - 48 upvotes, $0
  28. Open Redirection effects autodiscover.rockstargames.com to Rockstar Games - 48 upvotes, $0
  29. DOM XSS on https://www.rockstargames.com/GTAOnline/feedback to Rockstar Games - 46 upvotes, $0
  30. DOM based XSS on /GTAOnline/tw/starterpack/ to Rockstar Games - 46 upvotes, $0
  31. Stored XSS in profile activity feed messages to Rockstar Games - 44 upvotes, $1000
  32. CSRF in 'set.php' via age causes stored XSS on 'get.php' - http://www.rockstargames.com/php/videoplayer_cache/get.php' to Rockstar Games - 40 upvotes, $0
  33. Exposed CDN access token allows modification of all newly uploaded Snapmatic photos to Rockstar Games - 40 upvotes, $0
  34. Smuggle SocialClub's Facebook OAuth Code via Referer Leakage to Rockstar Games - 39 upvotes, $750
  35. <- Critical IDOR vulnerability in socialclub allow to insert and delete comments as another user and it discloses sensitive information -> to Rockstar Games - 39 upvotes, $0
  36. Image Injection vulnerability on screenshot-viewer/responsive/image may allow Facebook OAuth token theft. to Rockstar Games - 36 upvotes, $0
  37. Stored XSS on profile page via Steam display name to Rockstar Games - 35 upvotes, $1250
  38. Exploiting Misconfigured CORS to Steal User Information to Rockstar Games - 35 upvotes, $500
  39. DOM Based xss on https://www.rockstargames.com/ ( 1 ) to Rockstar Games - 34 upvotes, $0
  40. stored XSS (angular injection) in support.rockstargames.com using zendesk register form via name parameter to Rockstar Games - 31 upvotes, $1000
  41. Stored XSS in snapmatic comments to Rockstar Games - 30 upvotes, $1000
  42. Image Injection/XSS vulnerability affecting https://www.rockstargames.com/newswire/article to Rockstar Games - 29 upvotes, $0
  43. CSRF Vulnerability on post creation page /community/create-post.json to Rockstar Games - 29 upvotes, $0
  44. Uninstalling Rockstar Games Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication to Rockstar Games - 28 upvotes, $250
  45. XSS in http://www.rockstargames.com/theballadofgaytony/js/jquery.base.js to Rockstar Games - 28 upvotes, $0
  46. CSRF Vulnerability allows attackers to steal SocialClub private token. to Rockstar Games - 28 upvotes, $0
  47. DOM based reflected XSS in rockstargames.com/newswire/tags through cross domain ajax request to Rockstar Games - 27 upvotes, $0
  48. Reflected XSS in /Videos/ via calling a callback http://www.rockstargames.com/videos/#/?lb= to Rockstar Games - 27 upvotes, $0
  49. Reflected XSS via #tags= while using a callback in newswire http://www.rockstargames.com/newswire to Rockstar Games - 26 upvotes, $0
  50. Stored XSS on member post feed to Rockstar Games - 25 upvotes, $1000
  51. Login form on non-HTTPS page to Rockstar Games - 24 upvotes, $350
  52. use of unsafe host header leads to open redirect to Rockstar Games - 23 upvotes, $0
  53. Open redirect in https://www.rockstargames.com/GTAOnline/restricted-content/agegate/form may lead to Facebook OAuth token theft to Rockstar Games - 23 upvotes, $0
  54. Race condition vulnerability on "This Rocks" button. to Rockstar Games - 23 upvotes, $0
  55. Open redirect on https://signin.rockstargames.com/connect/authorize/rsg to Rockstar Games - 23 upvotes, $0
  56. Reflected XSS via Double Encoding to Rockstar Games - 22 upvotes, $500
  57. Information Disclosure in https://www.rockstargames.com/search to Rockstar Games - 22 upvotes, $0
  58. Minor Account Privacy can Set to Everyone. to Rockstar Games - 21 upvotes, $0
  59. [IMP] - Blind XSS in the admin panel for reviewing comments to Rockstar Games - 20 upvotes, $650
  60. phpinfo() on graph.rockstargames.com exposes sensitive information to Rockstar Games - 20 upvotes, $0
  61. Comments Denial of Service in socialclub.rockstargames.com to Rockstar Games - 19 upvotes, $0
  62. Stored XSS with CRLF injection via post message to user feed to Rockstar Games - 19 upvotes, $0
  63. Table and Column Exposure to Rockstar Games - 18 upvotes, $150
  64. Stored XSS via Send crew invite to Rockstar Games - 18 upvotes, $0
  65. Reflected XSS in reddeadredemption Site located at www.rockstargames.com/reddeadredemption to Rockstar Games - 17 upvotes, $0
  66. SocialClub's Facebook OAuth Theft through Warehouse XSS. to Rockstar Games - 17 upvotes, $0
  67. Dom based xss on https://www.rockstargames.com/ via returnUrl parameter to Rockstar Games - 17 upvotes, $0
  68. Open redirect affecting m.rockstargames.com/ to Rockstar Games - 16 upvotes, $0
  69. Dom based xss on /reddeadredemption2/br/videos to Rockstar Games - 16 upvotes, $0
  70. Control Character Injection In Messages to Rockstar Games - 15 upvotes, $0
  71. Client-side Template Injection in Search, user email/token leak and maybe sandbox escape to Rockstar Games - 15 upvotes, $0
  72. Image Injection on www.rockstargames.com/screenshot-viewer/responsive/image may allow facebook oauth token theft. to Rockstar Games - 14 upvotes, $0
  73. Image Injection vulnerability in www.rockstargames.com/IV/screens/1280x720Image.html to Rockstar Games - 14 upvotes, $0
  74. csrf in https://www.rockstargames.com/reddeadonline/feedback/submit.json to Rockstar Games - 14 upvotes, $0
  75. Source Code Disclosure (CGI) to Rockstar Games - 13 upvotes, $150
  76. Full path Disclosure in Rockstargames.com██████████ to Rockstar Games - 13 upvotes, $0
  77. Warehouse dom based xss may lead to Social Club Account Taker Over. to Rockstar Games - 13 upvotes, $0
  78. DOM BASED XSS ON https://www.rockstargames.com/GTAOnline/features to Rockstar Games - 13 upvotes, $0
  79. dom based xss in http://www.rockstargames.com/GTAOnline/ (Fix bypass) to Rockstar Games - 12 upvotes, $0
  80. Stored XSS on support.rockstargames.com to Rockstar Games - 11 upvotes, $1000
  81. Found CSRF Vulnerability in https://support.rockstargames.com/ to Rockstar Games - 11 upvotes, $150
  82. Leak IP internal to Rockstar Games - 11 upvotes, $0
  83. Flash injection vulnerability on /IV/imgPlayer/imageEmbed.swf to Rockstar Games - 11 upvotes, $0
  84. Your support community suffers from angularjs injection and must be fixed immediately [CRITICAL] to Rockstar Games - 10 upvotes, $0
  85. Referer Leakge in language changer may lead to FB token theft. to Rockstar Games - 10 upvotes, $0
  86. RDR2 game service method allows adding any player to a new Posse without consent to Rockstar Games - 10 upvotes, $0
  87. dom based xss in https://www.rockstargames.com/GTAOnline/ to Rockstar Games - 9 upvotes, $0
  88. Image Injection on /bully/anniversaryedition may lead to FB's OAuth Token Theft. to Rockstar Games - 9 upvotes, $0
  89. Modifying Sprunk vs eCola crew data to Rockstar Games - 9 upvotes, $0
  90. Profile bio at rockstar is accepting control characters to Rockstar Games - 8 upvotes, $0
  91. flash injection in http://www.rockstargames.com/IV/imgPlayer/imageEmbed.swf to Rockstar Games - 8 upvotes, $0
  92. Image Injection on /bully/anniversaryedition may lead to OAuth token theft. to Rockstar Games - 8 upvotes, $0
  93. Control characters incorrectly handled on Crew Status Update to Rockstar Games - 7 upvotes, $250
  94. insecure redirect in https://www.rockstargames.com to Rockstar Games - 7 upvotes, $0
  95. Image Injection vulnerability affecting www.rockstargames.com/careers may lead to Facebook OAuth Theft to Rockstar Games - 7 upvotes, $0
  96. Ability to post comments to a crew even after getting kicked out to Rockstar Games - 6 upvotes, $500
  97. SSLv3 POODLE Vulnerability to Rockstar Games - 6 upvotes, $0
  98. DOM based XSS on /GTAOnline/de/news/article via "returnUrl" parameter to Rockstar Games - 6 upvotes, $0
  99. CSRF Vulnerabiliy on Facebook Linkage Page Allows Full Account takerover of Socialclub Accounts. to Rockstar Games - 6 upvotes, $0
  100. Image injection on /screenshot-viewer/responsive/image ( FIX BYPASS) to Rockstar Games - 6 upvotes, $0
  101. image injection /screenshot-viewer/responsive/image (ANOTHER FIX BYPASS) to Rockstar Games - 6 upvotes, $0
  102. Dom based XSS on www.rockstargames.com/GTAOnline/features/freemode to Rockstar Games - 5 upvotes, $0
  103. Image injection /br/games/info may lead to phishing attacks or FB OAuth theft. to Rockstar Games - 5 upvotes, $0
  104. Referer Referer Header Leakage in language changer may lead to FB token theft to Rockstar Games - 3 upvotes, $0
  105. Image Injection Vulnerability on /bully/screens to Rockstar Games - 3 upvotes, $0