A potential remote code execution (RCE) vulnerability has been fixed in one of Starbucks' mobile domains.
The giant American coffee company is running a bug bounty program on HackerOne. A new vulnerability report filed by Kamil “ko2sec” Onur Özkaleli, first submitted on November 5 and made public on December 9, describes an RCE issue found on mobile.starbucks.com.sg, a platform for Singaporean.

According to the advisory, ko2sec discovered an .ashx endpoint on mobile.starbucks.com.sg that was intended to handle image. However, the endpoint did not restrict the files that were uploaded, meaning attackers could exploit the issue and potentially upload malicious files and remotely execute arbitrary code.
No CVE for the critical vulnerability, but it is rated 9.8. Ko2sec received $5,600 for findings .
The RCE isn’t the only bug the researcher has reported on Starbucks. In October, Ko2sec described an “account takeover exploit” on the Starbucks Singapore website that was triggered by open test. It was possible for targeted users – if they knew their email – to view their personal information and even use any funds loaded into account to make purchases.
The bug hunter received the sum of $6,000 for this report.
To date, Starbucks has received 1,068 vulnerability reports on HackerOne. The average amount paid for valid submissions ranges from $250 to $375, while critical bugs cost between $4,000 and $6,000. In total, the coffee chain has paid out over $640,000 to bug hunters.
