Infosecurity Magazine iconInfosecurity MagazineSep 23, 2026 ~4 min source read

GitGuardian: 474 Leaked GitHub App Private Keys Still Authenticate, Some Grant Admin Rights

Research found hundreds of exposed GitHub App RSA private keys in public code that remain valid, including keys able to read and write private repos and administer organizations.

Share this story

Send the public story page.

Useful takeaways from this story.

GitGuardian identified 474 leaked GitHub App private keys that still authenticate, corresponding to 440 distinct Apps.

Practical mitigation: rotate any potentially leaked App keys and implement continuous monitoring for exposures rather than one‑time checks.

The useful part

Of those, about 10% (474) still authenticated to GitHub's API as 440 distinct Apps. What the Leaked Keys Could Reach Some 72% of the affected Apps could read private repository content, and 207 could write to it. Another 44 had organization administration privileges, 40 could administer self-hosted runners and 98 could control workflows.

How it works

  • A key for the Crusher.dev test framework, leaked in 2020, still works even though the project has been unmaintained for three years, GitGuardian said.
  • The key for BuildBuddy's internal development App leaked in June 2025, with rights to write to and administer the company's main repository, potentially exposing its CLI users, self-hosted servers and SaaS...
  • To protect against this and similar threats, GitGuardian advised rotating any App key that may have leaked and monitoring for exposure continuously rather than once at setup.
  • Opinion 12 November 2025 1 Japanese Railway Operators Hit with Weekend Cyber Attacks News 29 September 2026 2 Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk News 25 September...
  • Enforcing AI Authority Before the Action Webinar 15:00 — 16:00, 8 October 2026 1 Experts Alarmed Over Gyazo's Breach of 490 Million Metadata Records News 21 September 2026 2 US:

What to take from it

Critical Infrastructure Braces for Sweeping New Cyber Reporting Rules News Feature 28 September 2026 4 Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns News 28 September 2026 5 Citrix Patches Critical Zero Days Under Active Exploitation News 28 September 2026 6 Who Authorized That Agent? Webinar 15:00 — 16:00, 3 September 2026 3 Human Risk in Cybersecurity: Opinion 3 July 2026 3 Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses Interview 7 July 2026 4 How World Cup Password Trends Can Increase Active Directory Risk Blog 23 June 2026 5 New CISA Guide Helps Agencies Adopt SASE For Zero Trust News 25 June 2026 6

Example or evidence

  • Users who never uninstalled the App remain exposed to private code theft.
  • BuildBuddy took the App down and found no sign of malicious use.
  • Most of the Apps were not marketplace products, with 59% having a single installation, which points to internal automation and one-off tooling that is easy to forget.
  • The key for Access Tokens for GitHub Actions, installed on about 300 organizations including Civica and Sierra Nevada Corp, leaked in January 2024 with rights to modify repository content and administer...

Details worth keeping

Hundreds of Leaked GitHub App Keys Still Authenticate. Unlike most credentials, GitHub App private keys never expire. Its maintainer rotated the key after GitGuardian's disclosure.

Related coverage

  • Devops: GitHub Enterprise Cloud now lets organizations export a full inventory of credentials, helping security teams identify stale, overprivileged and forgotten access across users, apps and automation.
  • Bleepingcomputer: Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
  • Theregister: Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app