<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Zapier Patched a Five-Flaw Chain That Could Have Hijacked Any Logged-In Account

Token Security found five chained flaws in Zapier that could allow account takeover. Zapier patched quickly and says it saw no evidence of exploitation.
Content Team

Security firm Token Security discovered five chained vulnerabilities in Zapier — a chain it calls Zapocalypse — that together could have let an attacker act as any logged-in user, starting with nothing more than a free account.

The path ran from Code by Zapier's Python sandbox through AWS credentials that had been scrubbed from the environment but left sitting in Lambda's memory, into an Amazon ECR registry holding 1,111 private repositories. One image's build metadata carried an npm publish token — unscoped, write-enabled, and flagged to bypass two-factor authentication.

That token could publish zapier-design-system, which loads in every authenticated session on zapier.com, so a bad actor could have created and rewritten automations as the user across Zapier's 8,000+ integrations. Connected services' OAuth tokens and API keys stay server-side, so those weren't directly exposed.

Yair Balilti of Token Security reported the chain on February 12. Zapier triaged it in four days, revoked the token, confirmed remediation by March 5, and paid its $3,000 maximum bounty — while committing to review that cap. Zapier says it has no evidence of exploitation beyond the research itself.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo