Insufficiently protected credentials in GitHub Desktop - #VU152206
Published: May 23, 2024 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose credentials.
The vulnerability exists due to improper credential handling in GitHub Desktop repository and submodule handling when processing repositories with submodules hosted on different hosts than the parent repository. A remote user can cause credentials to be transmitted to a different host to disclose credentials.
User interaction is required.