🚨 High Risk: Full Source Code Leaked via Exposed .git Repository on https://identity.kde.org
White Hat 127
xss.payload45 at gmail.com
Sat Sep 12 21:13:57 BST 2026
Severity: High
Bug Name: Exposed .git Repository (Source Code Leak)
Website: https://identity.kde.org
PoC URL: https://identity.kde.org/.git/HEAD
Description:
Your `.git` directory is publicly accessible, allowing an attacker to reconstruct your entire application's source code and commit history — including deleted files and old commits that may still contain secrets.
Impact:
- Complete source code disclosure, including business logic and any hardcoded secrets across history.
- Commit history can reveal removed credentials, internal comments, or unpatched vulnerabilities.
- Significant intellectual property and competitive exposure.
Suggested Fix:
- Block public access to `.git` at the server level immediately.
- Rotate any credentials ever committed to the repository, even if later removed (git history retains them).
- Ensure deployment processes never publish the `.git` directory to production.
White Hat Note:
Our goal is to make the internet safer through responsible testing and reporting. We are glad to help secure your site and hope it brings peace of mind. We would appreciate hearing about reward or acknowledgment you may offer.
More information about the kde-www
mailing list