← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Y Combinator Startup School application system vulnerable to score manipulation

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Founder found a vulnerability in Paxel, YC's scoring system.
  • Unvalidated HMAC allowed forging and pushing any score.
  • YC patched the issue and invited the founder to Startup School.
  • Over 1.2 million coders have used Paxel for YC applications.

Vulnerability Discovered in YC Application System

A founder identified a security vulnerability within Paxel, the software used by Y Combinator (YC) to score applicants for its Startup School program. The flaw stemmed from an unvalidated HMAC, which allowed an attacker to forge and submit arbitrary scores to YC's ranking database.

Impact on Startup School Applications

Paxel is utilized by over 1.2 million coders who upload reports to YC as part of their Startup School applications. The discovered vulnerability meant that the integrity of the scoring system for these applications could be compromised, potentially affecting the evaluation of numerous founders.

Y Combinator's Response

After the vulnerability was publicly disclosed, Y Combinator, specifically Jared Friedman, acknowledged the issue and announced that a patch had been implemented within hours. The founder who discovered the vulnerability was subsequently invited to attend Startup School in San Francisco.

Background of the Discovery

The founder began investigating Paxel after encountering it as a requirement for the Startup School 26’ application. The system uses a cURL script to install software that analyzes code and compiles a report for YC. The founder's curiosity led to the discovery of the security flaw.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 15 stories · Jul 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A founder discovered and exploited a vulnerability in Paxel, the system Y Combinator uses to score Startup School applicants, allowing manipulation of application scores. Y Combinator patched the vulnerability and invited the founder to attend Startup School after public disclosure. This highlights a security flaw in a widely used application process for a prominent startup accelerator.