{
  "id": 9507438,
  "title": "Leaked GitHub app keys retain live access",
  "url": "https://urgent.news/2026/09/24/leaked-github-app-keys-retain-live-access",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T06:52:09.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/leaked-github-app-keys-retain-live-access/"
  },
  "original_language": "en",
  "account": "Security researchers have discovered that hundreds of private GitHub App keys, used for authentication and access control, remain active despite being publicly exposed. GitGuardian analyzed over 500,000 leaked keys and found that 474, or roughly 10%, successfully authenticated against GitHub’s API, representing 440 distinct GitHub Apps. The compromised keys granted various levels of access, including repository content manipulation, self-hosted runner administration, and organization-wide control. GitHub's own documentation advises manual revocation of these keys, but many remain usable until explicitly removed. The issue spans from internal tools to applications used by major organizations like the CDC, underscoring the importance of rotating and securely storing private keys.",
  "summary": "Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found. GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated…",
  "key_points": [
    "474 GitHub App keys (10%) successfully authenticated against GitHub’s API.",
    "Many keys remain usable until manually revoked, affecting major organizations like the CDC."
  ],
  "editors_take": "The continued live access of leaked GitHub app keys highlights a significant security risk, as many remain usable despite being publicly exposed, allowing for unauthorized access and control.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}