Application security, Identity, API security, Supply chain, Data Security

Hundreds of GitHub App private keys leaked, granting broad access

Hundreds of GitHub App private keys have been found leaked in public code repositories, with some still active and granting significant administrative privileges to entire organizations, following insights from Infosecurity Magazine.

Research by GitGuardian revealed that out of thousands of exposed RSA private keys found in public GitHub contexts, a notable percentage remain functional. These keys, which do not expire, can be used to obtain API access tokens identical to those of the legitimate App. The potential impact is severe, with some leaked keys granting permissions to read and write private repository content, administer organizations, control self-hosted runners, and manage workflows. This could lead to complete organizational takeover or code execution on internal infrastructure.

Notable exposed entities include the Centers for Disease Control and Prevention (CDC) and BuildBuddy. The CDC's private App key, leaked in April 2025, had write access to repositories mediating between CDC repositories and its Azure infrastructure, potentially allowing arbitrary code execution. BuildBuddy's internal development App key, leaked in June 2025, granted rights to administer its main repository. GitGuardian advises continuous monitoring and rotating any potentially leaked App keys.

Source: Infosecurity Magazine

You can skip this ad in 5 seconds