CVE-2026-63728 HIGH

CVE-2026-63728: Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Vendor Gitleaks
Product gitleaks
Weakness CWE-1336
Published July 20, 2026
Last update July 22, 2026

CVSS base score

8.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan itself.

Key dates

02Disclosure timeline

July 20, 2026 CVE published
July 22, 2026 Record updated

Related vulnerabilities

04Related CVE