Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      HBAR Shorts Face $5 Million Risk if Price Breaks Key Level

      February 10, 2026

      Ethereum Holds $2,000 Support — Accumulation Keeps Recovery Hopes Alive

      February 10, 2026

      Miami Mansion Listed for 700 BTC as California Billionaire Tax Sparks Relocations

      February 10, 2026

      Solana Drops to 2-Year Lows — History Suggests a Bounce Toward $100 is Incoming

      February 10, 2026

      Bitget Cuts Stock Perps Fees to Zero for Makers Ahead of Earnings Season, Expanding Access Across Markets

      February 10, 2026
    • Technology

      Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

      February 10, 2026

      Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

      February 10, 2026

      New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

      February 10, 2026

      TikTok-Linked AI Video Tool Debuts With a Catch for the US

      February 10, 2026

      24 Best Last-Minute Valentine’s Day Gifts in 2025: Physical and Digital Options for Everyone

      February 10, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»DoorDash email spoofing vulnerability sparks messy disclosure dispute
    Technology

    DoorDash email spoofing vulnerability sparks messy disclosure dispute

    TechAiVerseBy TechAiVerseNovember 17, 2025No Comments6 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    DoorDash email spoofing vulnerability sparks messy disclosure dispute
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    DoorDash email spoofing vulnerability sparks messy disclosure dispute

    A vulnerability in DoorDash’s systems could allow anyone to send “official” DoorDash-themed emails right from company’s authorized servers, paving a near-perfect phishing channel.

    DoorDash has now patched the issue, but a contentious dispute has erupted between the researcher who reported the vulnerability and the company, with both sides accusing each other of acting improperly.

    Anyone could send ‘official’ DoorDash emails

    A simple flaw in DoorDash for Business platform could let anyone send fully branded “official” emails directly from no-reply@doordash.com.

    Discovered by a pseudonymous security researcher doublezero7, the flaw could be exploited by threat actors to launch highly convincing phishing campaigns and social engineering scams.

    Put simply, anyone could create a free DoorDash for Business account and then use backend admin dashboards to add a new ‘Employee’ (with an arbitrary name and email address), assign them meal-expense budgets, and craft emails containing arbitrary HTML.

    The resulting message, bearing DoorDash’s official template, would arrive seamlessly in the recipient’s mailbox, not spam:

    Researcher-crafted email sent via DoorDash’s official servers (BleepingComputer)

    The security researcher behind this discovery recently approached BleepingComputer and provided evidence of the vulnerability to demonstrate how it could be exploited by nefarious actors.

    “The root was Budget name input field. It was stored as raw text in database and forwarded to email where it would be rendered,” the researcher told BleepingComputer.

    “Using unclosed tags I could have altered the entire block of text about Budget information and using display:none it was possible to hide it completely and replace with crafted payload.”

    “It relied completely on email client defensive layers. Everything that passed, would be rendered. The input field enabled even on* events except for ‘onerror’ but these are filtered by email platforms,” continued the researcher.

    The “Claim Free 20$ Voucher” text shown in the above screenshot is a proof-of-concept HTML injection exploit crafted by the researcher on the DoorDash for Business backend, shown below:

    DoorDash for Business budgets backend used for creating emails (BleepingComputer)

    The researcher stated that emails sent by misuse of this feature was not limited to DoorDash customers or merchants—in other words, a threat actor could target almost any recipient with DoorDash-themed emails.

    The vulnerability is identical to the unaddressed flaw in Uber’s email systems that let just about anyone send emails from Uber.com, as revealed in 2022 by BleepingComputer.

    Escalated after 15 months

    Prior to contacting BleepingComputer, the researcher, frustrated with the long disclosure, published a brief vulnerability report summarizing the flaw and his disclosure attempts, while withholding any concrete technical details or proofs-of-concept.

    “The technical flaw was never complex—it was a classic stored payload rendered in a trusted email template,” they wrote at the time.

    The discoverer, however, took issue with the fact that the HackerOne report (# 2608277) filed for the vulnerability was closed as “Informative” around 17th of July, 2024, and “never escalated,” leaving the flaw exploitable for more than 15 months.

    According to the publicly visible timeline, and the researcher’s narration of events to BleepingComputer, it wasn’t until the week of November 3rd, that the flaw was patched, after the researcher directly emailed DoorDash repeatedly.

    “Without my public pressure, this vulnerability would still be active today,” claims the researcher.

    Ethical disclosure derailed, no bounty offered

    To establish a clear timeline, BleepingComputer performed an independent verification, and this is where the researcher’s account and DoorDash’s version of events begin to diverge.

    The researcher contends the company ignored the issue until pressured. The company says the pressure itself crossed ethical lines.

    According to a person familiar with the company’s handling of the vulnerability report, the interaction between the researcher and DoorDash broke down after the researcher demanded a substantial payment tied to disclosure timelines—something the source said the company viewed as outside the bounds of ethical bug bounty research. According to the source, the researcher also refused an offer of mediation and reiterated the financial demand.

    The researcher framed the report as a legitimate security finding deserving compensation. DoorDash has, however, deemed the issue out of scope and characterised the approach as feeling like extortion.

    A DoorDash spokesperson told BleepingComputer:

    “DoorDash operates a bug bounty program to work with security researchers to help find and fix potential security vulnerabilities.

    In this case, this individual attempted to extort DoorDash for money. They were subsequently banned from our bug bounty program.

    The issue reported fell outside the scope of our bug bounty program. Our security team has taken action to address the issue reported.

    We will continue to work with researchers who operate in good faith to protect our platform.”

    BleepingComputer also reached out to HackerOne to get full context.

    The bug bounty platform did not comment on why the researcher’s report was closed as “Informative.”

    A HackerOne spokesperson, however, shared with BleepingComputer:

    “We’ve reviewed this matter in coordination with our customer and confirmed that appropriate actions were taken consistent with HackerOne’s Code of Conduct and the customer’s program policy.

    HackerOne takes our Terms of Service seriously to ensure the safety and security of the platform, our customers, and the HackerOne community.

    If we determine that a community member has violated HackerOne’s Terms of Service, we will take prompt, appropriate action, which may include a permanent platform ban.”

    In emails to BleepingComputer, the researcher reiterated that the flaw went unpatched for an extended period and acknowledged using a “less ethical” approach when contacting the company directly, including demanding a payment:

    “My final email to DoorDash was a conditional offer to enter a compensated NDA in exchange for silence, given the history of severe neglect,” they wrote to BleepingComputer.

    “DoorDash fixed the bug within hours of the ultimatum (proving its criticality) but chose to ignore my payment demand and silently patch the flaw.”

    The now-patched flaw, while useful for spoofing convincing DoorDash emails, did not expose DoorDash user data or provide access to internal systems.

    Like any phishing vector, it required the recipient to be tricked into taking action, raising questions about its actual ‘criticality’.

    The researcher, however, sees the “silent fix” and their subsequent removal from the bug bounty program as retaliatory.

    “My decision to [disclose the vulnerability] stems directly from the fact that the company took my service for free, tried to hide their 16-month failure, and then attempted to silence me, which I believe is an unethical approach to security research.”

    “I honestly did not know if all my actions were right or not. But ultimately they patched the flaw so at least I accomplished that,” concluded the researcher to BleepingComputer.

    The case illustrates how vulnerability reporting can become fraught, and how misaligned expectations between researchers and companies can quickly lead to conflict.

    A source briefed on the matter told BleepingComputer the flaw is unrelated to the October DoorDash breach disclosed this month.


    The 2026 CISO Budget Benchmark

    It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

    Learn how top leaders are turning investment into measurable impact.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticlePennsylvania AG confirms data breach after INC Ransom attack
    Next Article The Internet May Keep Comparing This New Apple Product To Borat’s Mankini, But That Didn’t Stop It Selling Out
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    February 10, 2026

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    February 10, 2026

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    February 10, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025663 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025150 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 10, 2026

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and…

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    TikTok-Linked AI Video Tool Debuts With a Catch for the US

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Best PlayStation 5 Controllers in 2026: The Top PS5 Controllers From Sony, Razer, Nacon and More

    February 10, 20262 Views

    Keep Your Dry Streak Going With These 13 Best Nonalcoholic Drinks

    February 10, 20262 Views

    New Trump Phone Reportedly Costs More, Looks Different, and Isn’t Made in America

    February 10, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.