gyazo-2026 · Disclosed 2026-09-16
Gyazo: upload-server vulnerability and data access
An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Helpfeel reported patching, token revocation, investigation during suspension, and service resumption on September 27.
[s2]対応状況 / 9月27日追記
Evidence relevant to prevention
Insufficient evidence
Unknown patch timing prevents a neglect finding; inspect upload handling, database privileges, and deleted-data retention.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Specific vulnerability, CVE, and pre-intrusion patch availability are unknown; user records do not necessarily represent distinct people.
Sources
[s1] Helpfeel · Primary source
Gyazoにおける不正アクセスに関するお知らせ ↗Published 2026-09-16 · Reviewed 2026-10-02
[s2] Helpfeel · Primary source
Gyazoにおける不正アクセスに関するお知らせ(第2報) ↗Published 2026-09-25 · Reviewed 2026-10-02