From the source
Replit disclosed a vulnerability that may have exposed GitHub authentication tokens for less than 0.01% of its users, stemming from the GitHub import feature.
The tokens were written to the git reflog in public or HTTP-served Repls, potentially allowing unauthorized read/write access to repositories.
Replit fixed the vulnerability, revoked all existing tokens, and notified affected users.




