Impact
Gitleaks versions prior to 8.30.1 are vulnerable to template injection that permits an attacker who can supply or influence report templates to read arbitrary environment variables. By using the non‑hermetic Sprig template functions such as env, expandenv, and getHostByName, the attacker can extract credentials, tokens, and API keys. The extracted data can then be exfiltrated through DNS queries, including secrets discovered during the scan itself, leading to a confidentiality breach.
Affected Systems
The affected product is the open‑source tool Gitleaks, from the vendor gitleaks, specifically all releases before 8.30.1.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Attackers would need the ability to supply or modify report templates, likely requiring local or elevated access to the Gitleaks configuration. While the impact is primarily data exfiltration rather than remote code execution, the potential for compromising sensitive secrets makes it a serious concern.
OpenCVE Enrichment