Leaked GitHub app keys retain live access
Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found. GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated…
Security researchers have discovered that hundreds of private GitHub App keys, used for authentication and access control, remain active despite being publicly exposed. GitGuardian analyzed over 500,000 leaked keys and found that 474, or roughly 10%, successfully authenticated against GitHub’s API, representing 440 distinct GitHub Apps.
The compromised keys granted various levels of access, including repository content manipulation, self-hosted runner administration, and organization-wide control. GitHub's own documentation advises manual revocation of these keys, but many remain usable until explicitly removed. The issue spans from internal tools to applications used by major organizations like the CDC, underscoring the importance of rotating and securely storing private keys.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.