← Incident database

gyazo-2026 · Disclosed 2026-09-16

Gyazo: upload-server vulnerability and data access

An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Remote code execution affected the image-upload server on September 11 and was detected that evening.

    [s2]調査で判明した経緯
  • Reported fact

    The company confirmed access to 23.62 million user records and image metadata; metadata counts are not image-file exfiltration counts.

    [s2]影響範囲

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Helpfeel reported patching, token revocation, investigation during suspension, and service resumption on September 27.

    [s2]対応状況 / 9月27日追記

Evidence relevant to prevention

Insufficient evidence

Unknown patch timing prevents a neglect finding; inspect upload handling, database privileges, and deleted-data retention.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Specific vulnerability, CVE, and pre-intrusion patch availability are unknown; user records do not necessarily represent distinct people.

Sources

  1. [s1] Helpfeel · Primary source

    Gyazoにおける不正アクセスに関するお知らせ ↗

    Published 2026-09-16 · Reviewed 2026-10-02

  2. [s2] Helpfeel · Primary source

    Gyazoにおける不正アクセスに関するお知らせ(第2報) ↗

    Published 2026-09-25 · Reviewed 2026-10-02