{
  "retrieved_utc": "2026-09-22T22:25:27Z",
  "source": "HackerOne public disclosure record, https://hackerone.com/reports/{id}.json",
  "note": "Fields below are reproduced from HackerOne as published. No bounty amount appears in the retrieved payload for either report, so none is stated in the dossier.",
  "reports": [
    {
      "id": 291750,
      "url": "https://hackerone.com/reports/291750",
      "title": "Link filter protection bypass",
      "team": "valve",
      "weakness": "Open Redirect",
      "severity_rating": "medium",
      "state": "Closed",
      "substate": "resolved",
      "created_at": "2017-11-19T21:27:22.907Z",
      "disclosed_at": "2018-05-09T22:24:05.700Z",
      "vulnerability_information": "## Description\nHi, there is a protection bypass in the linkfilter function. By using the character 。 (%E3%80%82 url encoded) instead of a normal dot in urls, it is possible to bypass the blocking.\n\n## PoC\nNormal request : https://steamcommunity.com/linkfilter/?url=pornhub.com\n\n{F240919}\n\nBypass : https://steamcommunity.com/linkfilter/?url=pornhub%E3%80%82com\n\n{F240920}"
    },
    {
      "id": 1079561,
      "url": "https://hackerone.com/reports/1079561",
      "title": "Big Picture web browser leaks login cookies and discloses sensitive information (may lead to account takeover)",
      "team": "valve",
      "weakness": "Information Disclosure",
      "severity_rating": "high",
      "state": "Closed",
      "substate": "resolved",
      "created_at": "2021-01-15T20:51:31.914Z",
      "disclosed_at": "2021-09-21T21:42:03.659Z",
      "vulnerability_information": null
    }
  ]
}