CVE-2026-63728

Source
https://cve.org/CVERecord?id=CVE-2026-63728
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63728.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63728
Published
2026-07-20T23:32:34.476Z
Modified
2026-07-24T03:57:09.886543454Z
Severity
  • 8.1 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
Details

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan itself.

Database specific
{
    "cwe_ids": [
        "CWE-1336"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63728.json"
}
References

Affected packages

Git / github.com/gitleaks/gitleaks

Affected ranges

Type
GIT
Repo
https://github.com/gitleaks/gitleaks
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.30.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.2.0
v0.3.0
v0.4.0
v1.*
v1.0.0
v1.1.1
v1.1.2
v1.10.0
v1.11.0
v1.11.1
v1.12.0
v1.12.1
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.16.1
v1.17.0
v1.18.0
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.2.0
v1.2.1
v1.20.0
v1.21.0
v1.22.0
v1.23.0
v1.24.0
v1.25.0
v1.25.1
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.1.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.2.0
v3.2.1
v3.2.2
v3.3.0
v4.*
v4.0.0
v4.0.1
v4.1.0
v4.2.0
v4.3.0
v4.3.1
v5.*
v5.0.0
v5.0.1
v6.*
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v7.*
v7.0.0
v7.0.1
v7.0.2
v7.1.0
v7.1.1
v7.1.2
v7.2.0
v7.2.1
v7.2.2
v7.3.0
v7.4.0
v7.4.1
v7.5.0
v7.6.0
v7.6.1
v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.1.0
v8.1.1
v8.1.2
v8.1.3
v8.10.0
v8.10.1
v8.10.2
v8.10.3
v8.11.0
v8.11.1
v8.11.2
v8.12.0
v8.13.0
v8.14.0
v8.14.1
v8.15.0
v8.15.1
v8.15.2
v8.15.3
v8.15.4
v8.16.0
v8.16.1
v8.16.2
v8.16.3
v8.16.4
v8.17.0
v8.18.0
v8.18.1
v8.18.2
v8.18.3
v8.18.4
v8.19.0
v8.19.1
v8.19.2
v8.19.3
v8.2.0
v8.2.1
v8.2.2
v8.2.3
v8.2.4
v8.2.5
v8.2.6
v8.2.7
v8.20.0
v8.20.1
v8.21.0
v8.21.1
v8.21.2
v8.21.3
v8.21.4
v8.22.0
v8.22.1
v8.23.0
v8.23.1
v8.23.2
v8.23.3
v8.24.0
v8.24.1
v8.24.2
v8.24.3
v8.25.0
v8.25.1
v8.26.0
v8.27.0
v8.27.1
v8.27.2
v8.28.0
v8.29.0
v8.29.1
v8.3.0
v8.30.0
v8.5.0
v8.5.1
v8.5.2
v8.5.3
v8.6.0
v8.6.1
v8.7.0
v8.7.1
v8.7.2
v8.8.0
v8.8.1
v8.8.10
v8.8.11
v8.8.12
v8.8.2
v8.8.3
v8.8.4
v8.8.5
v8.8.6
v8.8.7
v8.8.8
v8.8.9
v8.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63728.json"