WhisperX tag archive

#Secret Leak

This page collects WhisperX intelligence signals tagged #Secret Leak. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-30 09:27:04 · GitHub Issues

1. SEC GitHub Workflow Flaw: Critical 'Pwn Request' Vulnerability in pr-loop.yml Exposes API Secrets

A critical security flaw in the SEC's GitHub Actions workflow, `pr-loop.yml`, creates a direct path for attackers to steal high-value API secrets, including the `ANTHROPIC_API_KEY` and `ALEXS_CODEX_KEY`. The vulnerability is a textbook 'pwn request' scenario, where the workflow's configuration grants it access to the r...

The Lab · 2026-04-21 19:22:58 · GitHub Issues

2. Semantic-Release v19.0.3 Patches Critical Secret Exposure Vulnerability (CVE-2022-31051)

A critical security vulnerability in the widely-used `semantic-release` automation tool has been patched, addressing a flaw that could expose sensitive secrets like API tokens and passwords to unauthorized actors. The vulnerability, tracked as CVE-2022-31051 (GHSA-x2pg-mjhr-2m5x), was present in versions prior to 19.0....