• Sources: primary
  • Summary: Helpfeel states that a third party exploited a vulnerability in the Gyazo image upload server on 2026-09-11 to execute arbitrary commands and reach the database, disclosing 23.62 million user records and 490 million image metadata records associated primarily with images registered in or before January 2019, about 14.4 percent of all image-related data, with a further 2.4 million records retrieved separately using filtering criteria. The disclosed user fields include password hashes, login session IDs, device IDs and X integration tokens, and the metadata includes the image IDs used to construct Gyazo URLs plus a list identifying which images are private. Helpfeel states it blocked all access routes and completed remediation of the exploited vulnerability by 2026-09-12, that it reviewed the authentication information involved and has already applied measures including invalidation and restrictions, that all users should change passwords, and that viewing of some images is temporarily disabled, while the vulnerability itself is not described.
  • Why it matters: Helpfeel says it invalidated the affected authentication data and closed the vulnerability by 2026-09-12 without disclosing the scope of either, and the exposed image IDs let a third party address private images directly.
  • Follow-up: Track the vulnerability detail, the session invalidation scope, and whether the private-image list was used.

send feedback on this story