MEDIUM 4.7 PyPI

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

GHSA-63wh-p5fx-h4vc · CVE-2025-10281

Published · Modified

Description

Summary

Due to unsafe URL handling, bbot's git_clone.py can be made to leak a user's github.com API key to an attacker-controlled webserver.

Impact

A user who has placed their github.com API key in the configuration for any of the following modules:

  • github_codesearch
  • github_workflows
  • gitlab
  • git_clone
  • github_usersearch
  • github_org

may leak it to an untrustworthy server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes