{
  "id": 8058299,
  "title": "CrowdSec Source Code Leak",
  "url": "https://urgent.news/2026/09/17/crowdsec-source-code-leak",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T15:34:01.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure"
  },
  "original_language": "en",
  "account": "On September 16, CrowdSec was notified of a source code leak involving their GitHub repository, which had occurred in May 2026. The organization confirmed the report and found that the leak only affected their private repositories.\n\nThe private portion of CrowdSec's source code includes the SaaS console, AWS Cloud routines, connectors, and automations. This code, while valuable, cannot directly harm CrowdSec as their efficiency relies on their network effect and size, which cannot be replicated by the code alone. The public-facing aspect of their code, the Security Engine, is openly available.\n\nThe leaked code was found to have been backdoored in May 2026, enabling unauthorized access to an API key that authorized the extraction of the private codebase. This exploitation was likely due to the Tanstack compromise, similar to the Mistral AI case. However, the leak was only exploitable for a brief period and can no longer be used maliciously.\n\nCrowdSec promptly rotated all necessary tokens and credentials to prevent any further incidents. They expressed gratitude to Fuites Infos for their timely and professional reporting of the issue.\n\nTo enhance the reliability of their Central API (CAPI) as usage continues to grow, CrowdSec has implemented rate limiting. This measure helps prevent misconfigured or broken deployments from generating excessive traffic and ensures fair access and consistent performance for all users. Additionally, they have introduced CVE Explorer, a tool to help organizations prioritize threats and vulnerabilities.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}