bug-bounty 3 Path Traversal in File Upload via GraphQL API Mar 11, 2025 Auth Token Theft via CORS Misconfiguration Mar 8, 2025 Privilege Escalation via Chat Permissions Bypass Feb 7, 2024