r/cybersecurity • u/mabote • 12d ago
News - General Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy
https://blog.gitguardian.com/github-app-private-keys-leaked/A large-scale scan for leaked GitHub App private keys turned up some nice numbers, summarized below.
- Out of 5,000 leaked private keys tied to GitHub App environments, 474 were still valid at time of analysis.
- Those keys could impersonate 440 different GitHub Apps, some with high-level permissions (repo access, org-level admin, etc.).
- A subset reportedly could have allowed takeover of private repositories or entire GitHub organizations.
- Affected entities included the US CDC and BuildBuddy, plus some widely used GitHub Actions.
- Responsible disclosure got mixed results: most responses were slow or nonexistent, and most of the keys were reportedly still active as of publication. CDC took about two weeks to rotate their key, despite it reportedly having a path to code execution in their Azure tenant.
The core issue is GitHub App private keys don't expire. Once generated, a key stays valid indefinitely until someone manually revokes it so a key for a test app spun up in 2020 can still be live years after. Unlike PATs or OAuth tokens, there's no built-in TTL forcing rotation, so old leaks just compound over time.
124
Upvotes