git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] git-credential-libsecret writes secret to stdout on store

From
Mantas Mikulėnas <grawity@gmail.com>
Date
Apr 21, 2026, 11:37 UTC
Message-ID
<2d5b37b0-3442-42f8-81f4-18b48e95a617@gmail.com>
In-Reply-To
<b7b6b94c-7e42-42a5-95e5-d44a54d6da0f@wateringcan.de>
On 21/04/2026 14.03, Lutz-Christian Quander wrote:
Show 14 quoted lines
> The documented pattern for seeding credentials non-interactively is:
>
>     printf "protocol=...\nhost=...\nusername=...\npassword=...\n\n" | 
> git-credential-<helper> store
>
> Running this at a terminal prints the secret into scrollback.
> Running it in a shell script whose stdout goes to a log file
> persists the secret in that log. Running it in CI captures the
> secret in the pipeline artefact. Every real-world use of the
> documented pattern is affected.
>
> Severity is moderate: the leak requires the user to run a legitimate
> command -- no attacker-controlled input path -- but the leak happens
> on the "correct" documented workflow, silently, with exit code 0.

Is it actually the correct documented workflow? I couldn't find it in the Git docs. My understanding was that writing to "git credential approve" was the sole user interface, while "git-credential-<helper> store" was the internal interface between the git-credential builtin and the helper.

Previous: Lutz-Christian QuanderNext: Mantas Mikulėnas
Message 2 of 4 in “[BUG] git-credential-libsecret writes secret to stdout on store”
  1. Lutz-Christian QuanderApr 21, 2026
  2. Mantas MikulėnasApr 21, 2026
  3. Mantas MikulėnasApr 22, 2026
  4. Phillip WoodApr 22, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.