CVE-2026-63728
MEDIUMGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
Title source: cnaDescription
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan itself.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/gitleaks/gitleaks/commit/83d9cd684c87d95d656c1458ef04895a7f1cbd8e
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/gitleaks-secret-exfiltration-via-non-hermetic-sprig-template-functions-in-report-template-feature
Scores
CVSS v3
6.3
EPSS
0.0014
EPSS Percentile
4.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1336
Status
published
Products (1)
gitleaks/gitleaks
< 8.30.1
Published
Jul 21, 2026
Tracked Since
Jul 21, 2026