- Sources: Cyera research, HN submission
- Summary: Cyera researchers defined a full-access Composio key in their own lab to simulate an external attacker holding a leaked key, and a single read-only call returned the Gmail access and refresh tokens, the GitHub bearer token, and the CircleCI API key. No affected versions apply. Composio is a hosted platform with no version surface, and the finding is a permissions and token-scope design issue rather than a versioned defect. This is vendor research from a company selling the remedy, so only the lab demonstration is carried here. The surrounding census figures on exposed credentials and integration applications are vendor-reported against an undisclosed customer base and are not independently checkable.
- Why it matters: Rotating the integration platform key does not end the incident, because each downstream grant keeps working against Google, GitHub, and CircleCI until it is revoked separately.
send feedback on this story