HIGH
gitleaks
CVE published 2026-07-21
CVE-2026-63728
CVE-2026-63728 is a template injection vulnerability in Gitleaks prior to 8.30.1. Attackers can leverage non-hermetic Sprig template functions to read arbitrary environment variables and exfiltrate sensitive data by crafting malicious report templates. This vulnerability allows attackers who can supply or influence report templates to extract credentials, tokens, and API keys from the host process and exf [truncated]