Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

CVE-2026-63728: Gitleaks Report Templates Can Leak Sensitive Data

CVE-2026-63728 CVE-2026-63728
Summary

Gitleaks before version 8.30.1 has a security flaw that allows attackers to access sensitive information, like API keys and credentials, by creating malicious report templates. This can happen if an attacker has control over or can influence the report templates used by Gitleaks. To stay secure, update Gitleaks to version 8.30.1 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gitleaks gitleaks < 8.30.1
Original title
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensit...
Original description
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan itself.
mitre CVSS3.1 6.3
Vulnerability type
CWE-1336
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 20 Jul 2026