#0x57

Public Swagger / OpenAPI documentation on 5 Jupiter production APIs reveals every internal route, including the 1000-JUP token-verify payment flow

@brudasubmitted a report toJupiterMay 14, 2026 at 12:22
Severity
LOW
CVSS
5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability TypeSecurity Misconfiguration
Asset*.jup.ag - Jupiter Domain
Endpointhttps://token-verify-api.jup.ag/docs

Description

Steps to Reproduce

Impact

Activity

@thibaultclosed the report asInformative
May 14
@raccoonsdisclosed this reportPublic Disclosure
May 22