# Replit — April 2 Potential GitHub Credentials Exposure

- Company: Replit (replit.com)
- Announced: 2023-04-04T02:00:00+00:00
- Category: safety-policy-update
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://replit.com/blog/april-02-potential-github-credentials-exposure
- Record: https://forck.live/items/18120-april-2-potential-github-credentials-exposure
- Subject: Replit Agent

Replit disclosed a vulnerability that may have exposed GitHub authentication tokens for less than 0.01% of its users, stemming from the GitHub import feature. The tokens were written to the git reflog in public or HTTP-served Repls, potentially allowing unauthorized read/write access to repositories. Replit fixed the vulnerability, revoked all existing tokens, and notified affected users.

## Evidence

Verbatim from https://replit.com/blog/april-02-potential-github-credentials-exposure:

> Yesterday, on April 2, 2023, Replit discovered a site vulnerability that may have exposed GitHub auth tokens for <0.01% of Replit users, stemming from use of the GitHub import feature.

---

Record: https://forck.live/items/18120-april-2-potential-github-credentials-exposure
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
