Template Injection Vulnerability in Gitleaks by GitLeaks
CVE-2026-63728

8.1HIGH

Key Information:

Vendor

Gitleaks

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63728?

Gitleaks versions prior to 8.30.1 are affected by a template injection vulnerability that enables attackers to exploit report templates. By manipulating these templates, adversaries can leverage non-hermetic Sprig functions such as env, expandenv, and getHostByName to access arbitrary environment variables. This could lead to the unauthorized extraction of sensitive information, including credentials, API keys, and tokens, which may be exfiltrated through DNS queries. It is crucial for users to upgrade to the latest version to safeguard against this risk.

Affected Version(s)

gitleaks 0

References

CVSS V4

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fatih Çelik
.