2026-09-18 · view entry permalink →
Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records
Helpfeel Inc. (Kyoto, Japan) disclosed on 2026-09-16 that a third party exploited a vulnerability in the image-upload server of Gyazo, its screenshot-sharing service, on 2026-09-11, gaining unauthorized system access and the ability to execute arbitrary commands, then reaching Gyazo's database (Helpfeel Inc., 2026-09-16); Helpfeel has not named the flaw class or assigned a CVE. Roughly 23.62 million user records were exposed (name, email, password hash, user ID, device ID, login-session ID, X/Google SSO tokens, profile data, language preference, registration and last-login timestamps, subscription plan and billing status, excluding payment-card numbers) plus roughly 490 million image-metadata records, mostly pre-2019, and metadata for a further 2.4 million images, including a link built from a 32-character image ID used to construct the access URL (The Hacker News, 2026-09-17), plus upload IP, User-Agent, EXIF location data, OCR-extracted text, and a hashed passphrase for password-protected private images (Helpfeel Inc., 2026-09-16). Gyazo's default privacy setting for an image relies entirely on the image ID in its URL staying secret, distinct from the stricter "Only me" or password-protected settings (The Hacker News, 2026-09-17); the leaked IDs directly defeat the default setting, and Helpfeel confirms the attacker also obtained a list identifying which images were marked private, so it "cannot rule out" unauthorized viewing of private content (Helpfeel Inc., 2026-09-16). Helpfeel's own public status page described the outage only as "emergency maintenance" on September 14 and 15 and did not disclose a breach until the September 16 notice, filing a report with Japan's Personal Information Protection Commission the day before (The Hacker News, 2026-09-17). Helpfeel's other two products, Helpfeel and Cosense, run on separate infrastructure and were not found to have any unauthorized data disclosure (Helpfeel Inc., 2026-09-16).
On September 11, 2026, a third party exploited a vulnerability in Gyazo's image upload server to gain unauthorized access to our systems and execute arbitrary commands.
We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.