www.infosecurity-magazine.com 23 Sept 2026, 15:00 UTC

Hundreds of Exposed GitHub App Keys Still Grant Private Access

Hundreds of Exposed GitHub App Keys Still Grant Private Access
CyberSIXT Evidence Panel Source marked as original reporting

HUNDREDS of GitHub App private keys exposed in public code remain valid, according to research by GitGuardian. The company identified more than 500,000 exposed RSA private keys, narrowing these to 4,802 associated with a GitHub App and App ID. Of those, 474 keys still authenticated to GitHub’s API, representing 440 distinct Apps. GitHub App private keys do not expire automatically and remain usable until manually deleted, allowing anyone who obtains one to request access tokens acting as the App.

The affected Apps often had significant permissions: 72% could read private repositories, 207 could write to them, 44 had organisation administration privileges, 40 could administer self-hosted runners and 98 could control workflows. GitGuardian said these capabilities could enable an organisation takeover or code execution on internal infrastructure. One key belonging to Access Tokens for GitHub Actions, installed across about 300 organisations, was leaked in January 2024 and was rotated after disclosure. A Crusher.dev key leaked in 2020 reportedly still works, leaving users who have not removed the App exposed.

Other cases involved the US Centers for Disease Control and Prevention, where a key leaked in April 2025 could potentially have enabled code execution in its Azure tenant, although GitGuardian found no evidence it had been used. The credentials were reported on 4 September and revoked on 18 September. BuildBuddy also removed an exposed internal App and found no sign of malicious use. GitGuardian recommended rotating any potentially leaked App keys and continuously monitoring for exposure.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline