🚨 High Risk: Full Source Code Leaked via Exposed .git Repository on https://identity.kde.org

White Hat 127 xss.payload45 at gmail.com
Sat Sep 12 21:13:57 BST 2026


Severity: High
Bug Name: Exposed .git Repository (Source Code Leak)
Website: https://identity.kde.org
PoC URL: https://identity.kde.org/.git/HEAD

Description:
Your `.git` directory is publicly accessible, allowing an attacker to reconstruct your entire application's source code and commit history — including deleted files and old commits that may still contain secrets.

Impact:
- Complete source code disclosure, including business logic and any hardcoded secrets across history.
- Commit history can reveal removed credentials, internal comments, or unpatched vulnerabilities.
- Significant intellectual property and competitive exposure.

Suggested Fix:
- Block public access to `.git` at the server level immediately.
- Rotate any credentials ever committed to the repository, even if later removed (git history retains them).
- Ensure deployment processes never publish the `.git` directory to production.

White Hat Note:
Our goal is to make the internet safer through responsible testing and reporting. We are glad to help secure your site and hope it brings peace of mind. We would appreciate hearing about reward or acknowledgment you may offer.


More information about the kde-www mailing list