Hundreds of Leaked GitHub App Keys Still Authenticate
GitGuardian found 4,802 exposed GitHub App RSA private keys in public code, and 474 of them (about 10%) still authenticate to GitHub's API as 440 distinct Apps. GitHub App keys never expire, and 44 of the affected Apps had organization admin privileges.
- 474 of 4,802 leaked keys still authenticate to GitHub's API
- 72% of affected Apps could read private repos, 207 could write
- 44 Apps had org admin rights, 98 could control workflows
- Access Tokens for GitHub Actions key worked across ~300 orgs
Read next
Security