CTIPilot
← Back to Daily brief 2026-09-18
NOTABLENATOB2incident

Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records

Helpfeel's 'unguessable link' privacy model for Gyazo collapsed once the image IDs themselves leaked from the backend

Analysis

Helpfeel Inc. (Kyoto, Japan) disclosed on 2026-09-16 that a third party exploited a vulnerability in the image-upload server of Gyazo, its screenshot-sharing service, on 2026-09-11, gaining unauthorized system access and the ability to execute arbitrary commands, then reaching Gyazo's database (Helpfeel Inc., 2026-09-16); Helpfeel has not named the flaw class or assigned a CVE. Roughly 23.62 million user records were exposed (name, email, password hash, user ID, device ID, login-session ID, X/Google SSO tokens, profile data, language preference, registration and last-login timestamps, subscription plan and billing status, excluding payment-card numbers) plus roughly 490 million image-metadata records, mostly pre-2019, and metadata for a further 2.4 million images, including a link built from a 32-character image ID used to construct the access URL (The Hacker News, 2026-09-17), plus upload IP, User-Agent, EXIF location data, OCR-extracted text, and a hashed passphrase for password-protected private images (Helpfeel Inc., 2026-09-16). Gyazo's default privacy setting for an image relies entirely on the image ID in its URL staying secret, distinct from the stricter "Only me" or password-protected settings (The Hacker News, 2026-09-17); the leaked IDs directly defeat the default setting, and Helpfeel confirms the attacker also obtained a list identifying which images were marked private, so it "cannot rule out" unauthorized viewing of private content (Helpfeel Inc., 2026-09-16). Helpfeel's own public status page described the outage only as "emergency maintenance" on September 14 and 15 and did not disclose a breach until the September 16 notice, filing a report with Japan's Personal Information Protection Commission the day before (The Hacker News, 2026-09-17). Helpfeel's other two products, Helpfeel and Cosense, run on separate infrastructure and were not found to have any unauthorized data disclosure (Helpfeel Inc., 2026-09-16).

Cited evidence

On September 11, 2026, a third party exploited a vulnerability in Gyazo's image upload server to gain unauthorized access to our systems and execute arbitrary commands.

We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.

Helpfeel Inc. 2026-09-16

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.