hn.today

CrowdSec Source Code Leak

crowdsec.net101 points30 comments
Screenshot of CrowdSec Source Code Leak

On September 16, the team disclosed a May 2026 source-code exposure involving their GitHub repositories. The codebase is split between a public Free Open Source Security Engine and private repositories that held the SaaS console source, AWS cloud routines, connectors and automations. Approximately 300 repositories were exposed when counting the 130+ public ones, though that number mainly reflects repository subdivision rather than a large volume of unique material. An API token used by the CI/CD system was present in the leak, but no client data, logins, passwords, organization names, personal data or client logs were exposed. The team hunted for any credentials or tokens that would allow lateral movement and found none. Much of the leaked private code has evolved since May, and routine audits were in place.

The incident is limited to the company: leaked code has value but cannot reproduce the organization’s network effect or be readily repurposed elsewhere, so it does not pose immediate harm. Investigation attributes the intrusion vector to a compromised Tanstack component backdoored to extract a key granting repository read access, mirroring the Mistral AI case; the vulnerability was exploitable only for a short window in May. Remediation steps included rotating all required tokens and credentials and instituting ongoing monitoring for abnormal activity. The disclosure thanks Fuites Infos for reporting the issue.

Read on crowdsec.net30 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.