HeadlinesBriefing favicon HeadlinesBriefing.com

CrowdSec bestätigt Quellcode-Leck im Mai 2026 über Tanstack

Hacker News •
×

On September 16, CrowdSec confirmed a source code leak from its GitHub repository that occurred in May 2026. The breach involved private repositories containing the SaaS console, AWS Cloud routines, connectors, and automations, while the public Security Engine was unaffected. The company stated the report of 300 repositories is accurate but includes over 130 public ones.

No client data, credentials, or PII were exposed, and CrowdSec does not store client logs. The team found no tokens or sensitive leaks enabling lateral movement. The leaked code has evolved significantly since May and cannot be leveraged outside CrowdSec's ecosystem.

The likely vector was a compromised Tanstack component used internally in May, which was backdoored to extract an API key with read access to the private codebase. The vulnerability window was short-lived. CrowdSec immediately rotated all tokens and credentials and thanked Fuites Infos for responsible disclosure. Investigation continues with monitoring for abnormal activity.