Executive brief
The ATLAS-EPIC repository, which manages data pipelines for Palantir Foundry, was found to contain hardcoded authentication credentials. An attacker could use these credentials to gain unauthorized access to sensitive health information and protected data pipelines. Organizations using this repository should immediately rotate their security keys and remove the exposed files from their version history.
Technical details
A Use of Hard-coded Credentials (CWE-798) vulnerability exists in the ATLAS-EPIC repository. The 'auth/keys' directory contains a publicly accessible, unencrypted 2048-bit RSA private key (private_key.pem) and a corresponding client ID. An unauthenticated remote attacker can use these credentials to authenticate against FHIR endpoints and access protected Palantir Foundry data pipelines. The vulnerability was identified in commit f29312c and requires the removal of the credentials from the repository history and the rotation of keys within the Foundry environment.
Affected products
- gsiegel14 ATLAS-EPIC commit f29312c and earlier
Timeline
- 2025-08-25: other: Vulnerability discovered during repository audit
- 2025-10-11: advisory: Public advisory published by xancatos
- 2025-10-16: disclosed: CVE published to NVD