Insufficiently protected credentials in GitHub Desktop - #VU152206

 

Insufficiently protected credentials in GitHub Desktop - #VU152206

Published: May 23, 2024 / Updated: September 25, 2026


Vulnerability identifier: #VU152206
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose credentials.

The vulnerability exists due to improper credential handling in GitHub Desktop repository and submodule handling when processing repositories with submodules hosted on different hosts than the parent repository. A remote user can cause credentials to be transmitted to a different host to disclose credentials.

User interaction is required.


Affected software

GitHub Desktop

Remediation

Install security update from vendor's website.

GitHub Desktop - update to 3.3.15

External References

Related Security Bulletins