hey, this vuln seems familiar!
this has actually been a thing for over two years now.
how do i know? its been almost two years since i reported the exact same vulnerability to twitter's hackerone 🙃
twitter's security & bug bounty program is laughably bad, a thread
@GinaZwicky they have to imply that it's something to think about in the future when you vote for them, because they're doing the right thing and still have plenty of time to save us, and not that they have already deeply failed and will continue to make the problem worse