Home Depot allegedly left its internal systems at risk for more than a year


  • Home Depot exposed a GitHub token for a year, providing access to critical internal systems
  • The researchers’ warnings were ignored until media intervention, after which the token was revoked.
  • Similar leaks on GitHub/GitLab show widespread risks from hardcoded secrets and misconfigured repositories.

Home Depot kept access to its internal systems open for more than a year to anyone who knew where to look, experts warned.

Security researcher Ben Zimmermann recently found a released GitHub access token belonging to a Home Depot employee.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top