Hundreds of Leaked GitHub App Keys Still Grant Access, Some With Organization Admin Rights
GitGuardian found 474 of 4,802 publicly exposed GitHub App private keys still authenticate, some enabling repository access and full organization takeover because such keys never expire unless manually revoked.
GitGuardian analyzed 4,802 publicly exposed RSA private keys paired with GitHub App IDs, collected since 2019, and found 474 (roughly 10 percent) still authenticated as 440 distinct Apps. GitHub App private keys do not expire until manually deleted, and a holder can mint access tokens indistinguishable from the App itself. About 72 percent of the valid keys could read private repository content, 207 could write to it, 98 could control workflows, 40 could administer self-hosted runners, and 44 held organization-administration rights capable of enabling organization takeover. One App for Access Tokens for GitHub Actions, whose key was exposed in January 2024, was installed on roughly 300 organizations, including Civica and Sierra Nevada Corp. Named affected parties included the CDC, BuildBuddy, and Crusher.dev: a CDC App key leaked in a CDCGov repository in April 2025 was revoked on September 18, 2025 after disclosure, BuildBuddy and the Actions maintainer also rotated keys and reported no malicious use, and a Crusher.dev key from 2020 reportedly still works on an unmaintained project.
- 474 of 4,802 publicly exposed GitHub App private keys (collected since 2019) still authenticated as 440 distinct Apps, roughly 10 percent.
- About 72 percent of valid keys could read private repositories; 207 could write repository content.
- 44 Apps held organization-administration rights; 98 could control workflows and 40 could administer self-hosted runners.
- A shared Access Tokens for GitHub Actions App, exposed January 2024, was installed on roughly 300 organizations, including Civica and Sierra Nevada Corp.
- A CDC App key leaked April 2025 in a CDCGov repository was revoked September 18, 2025 after disclosure; BuildBuddy and the Actions maintainer rotated keys and reported no malicious use.
- A 2020 Crusher.dev key still works on an unmaintained project.
- GitHub App private keys never expire; only manual revocation invalidates them.
Coverage timelineoldest first · each row is one article
- · 3d agoHundreds of Leaked GitHub App Keys Still Authenticate
Infosecurity Magazine· 76
GitGuardian found 474 leaked GitHub App private keys still authenticate, some with organization admin rights.
- · 3d agoGitHub App keys can still enable takeovers long after they are forgotten
CSO Online· 73
GitGuardian found 474 still-valid leaked GitHub App keys that can enable repository access and organization takeovers.