WhisperX tag archive

#api_key

This page collects WhisperX intelligence signals tagged #api_key. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-27 19:27:29 · GitHub Issues

1. Critical Security Fix: Hardcoded Stripe Live API Key Exposed in Source Code and Admin Endpoint

A critical security vulnerability has been automatically patched after a hardcoded Stripe live API key was discovered in a project's source code and exposed via an admin dashboard endpoint. The key, identified as 'stripe_live_key_EXAMPLE_1234567890abcdef', was embedded directly within the `src/config.js` file, represen...

The Lab · 2026-04-06 03:26:59 · GitHub Issues

2. Security Review Exposes Critical Gap: No Rotation Plan for CIAM's Core Social Login API Key

A critical security gap has been exposed within the platform's CIAM (Customer Identity and Access Management) infrastructure. A recent security review (SR-1) identified that the `CIAM_RELOAD_API_KEY`, a pre-shared key used to authenticate the SIGHUP sidecar for social login configuration reloads, lacks any documented r...