Re: [BUG] git-credential-libsecret writes secret to stdout on store
- From
Mantas Mikulėnas <grawity@gmail.com>
- Date
- Apr 21, 2026, 11:37 UTC
- Message-ID
- <2d5b37b0-3442-42f8-81f4-18b48e95a617@gmail.com>
- In-Reply-To
- <b7b6b94c-7e42-42a5-95e5-d44a54d6da0f@wateringcan.de>
On 21/04/2026 14.03, Lutz-Christian Quander wrote:
Show 14 quoted lines
> The documented pattern for seeding credentials non-interactively is: > > printf "protocol=...\nhost=...\nusername=...\npassword=...\n\n" | > git-credential-<helper> store > > Running this at a terminal prints the secret into scrollback. > Running it in a shell script whose stdout goes to a log file > persists the secret in that log. Running it in CI captures the > secret in the pipeline artefact. Every real-world use of the > documented pattern is affected. > > Severity is moderate: the leak requires the user to run a legitimate > command -- no attacker-controlled input path -- but the leak happens > on the "correct" documented workflow, silently, with exit code 0.
Is it actually the correct documented workflow? I couldn't find it in the Git docs. My understanding was that writing to "git credential approve" was the sole user interface, while "git-credential-<helper> store" was the internal interface between the git-credential builtin and the helper.