Junglewise Threat Intelligence

CVE-2026-63728: Gitleaks template injection in report-template feature

CVE-2026-63728 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Executive brief

Gitleaks, a tool used to find sensitive secrets like passwords and API keys in code, is vulnerable to a flaw in its reporting feature. If an attacker can convince a user to use a malicious report template, they can steal the secrets found during the scan as well as sensitive system information (environment variables). This data is then sent to the attacker's server via hidden network requests, potentially leading to the compromise of cloud credentials or private databases.

Technical details

A template injection vulnerability exists in Gitleaks' report-template feature due to the use of non-hermetic functions from the Sprig template library. Specifically, the inclusion of functions like 'env', 'expandenv', and 'getHostByName' allows a malicious template to access the host process's environment variables and perform DNS lookups. An attacker can craft a template that encodes discovered secrets or environment variables (such as AWS keys or API tokens) into subdomains and exfiltrates them via DNS queries to an attacker-controlled listener. The vulnerability is triggered when a user runs a Gitleaks scan using a compromised or untrusted template file. This issue was resolved in version 8.30.1 by switching to hermetic template functions that exclude OS and network-level operations.

Affected products

  • Gitleaks Gitleaks < 8.30.1

Timeline

  • 2026-03-25: disclosed: Vulnerability discovered and blog post published by Fatih Çelik
  • 2026-07-20: advisory: VulnCheck advisory published
  • 2026-07-21: advisory: NVD publication date
  • 8.30.1: patched

References