LmCast :: Stay tuned in

CrowdSec Source Code Leak

Recorded: Sept. 17, 2026, 5 p.m.

Original Summarized

CrowdSec Statement: Source Code Exposure in May 2026Download the latest Vulnerability & Exploitation Report
Download nowCrowdSecProductsSolutionsPricingOur DataResourcesCompanySearchLog inCrowdSec BlogAnnouncementSep 17, 2026CrowdSec Statement: Source Code Exposure in May 2026
On September 16, CrowdSec was informed of a source code leak involving our GitHub repository, which occurred in May 2026. Our team verified and confirmed the report. CrowdSec source code consists of two parts: a private one and another that hosts our Free Open Source Software (i.e., the Security Engine), which is public by design and therefore out of scope. The private part, though, contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations. 
The news headline claiming 300 different repositories is accurate (when you include the 130+ public ones), though that number mostly reflects the code’s subdivision rather than a specific volume. We do not confirm any “other file contained” or “internal development material”, since all the code is published in these repositories. The API related information is the token used by the CI/CD component itself. (see below)
No client data, login/password, name, organization, or anything else was leaked, and CrowdSec doesn’t store PII or client logs; the impact is limited to CrowdSec. Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far.
The code contained in these private repositories has value but cannot really harm CrowdSec, since our efficiency depends on our network effect and size, which code alone can’t replicate. We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity. Also, using it outside of CrowdSec seems unlikely because it only interacts with our data and tools and cannot really be leveraged in another context. 
We will keep you updated as we continue investigating, but the Tanstack compromise is very likely to have been the leak vector (more about it here), as in the case of the Mistral AI case. This component was used in our organization in May and appears to have been backdoored to extract an API key with authorization to read the private codebase. The leak was only exploitable during a short timeframe in May 2026.
We nevertheless immediately rotated all required tokens & credentials to prevent further incidents.
The team would like to thank Fuites Infos for their timely, professional outreach in reporting the issue.
WRITTEN BYThe CrowdSec TeamYou may also likeAnnouncementIntroducing Live Exploit Tracker: Know What’s Exploited, Act FasterSee which CVEs are actively exploited in the wild. Live Exploit Tracker helps you prioritize faster using real attack activity, IPs, and IoCs.
Feb 5, 2026AnnouncementProtecting CAPI reliability: Introducing rate limiting on CrowdSec’s Central APITo keep CrowdSec’s Central API (CAPI) reliable as usage continues to grow, we’ve introduced rate limiting. This change helps prevent misconfigured or broken deployments from generating excessive traffic, ensuring fair access and consistent performance for everyone.
Dec 18, 2025AnnouncementExplore and Prioritize Vulnerabilities with the CrowdSec CVE ExplorerIntroducing our new CVE Explorer. Learn what it is and how it can help your organization prioritize threats and vulnerabilities.
Aug 21, 2025ProductCrowdSec Security EngineCrowdSec ConsoleCrowdSec IP ReputationCrowdSec BlocklistsLive Exploit TrackerPricingCommunityDocumentationAPI DocumentationAmbassadorsSwag StoreCompanyBlogOur storyCareersList of partnersWhy become a partnerGeneral informationContactFAQRemove an IP from the blocklistCommunity Pulse NewsletterStay in the loop on all things CrowdSecSubscribe to the newsletterLegal noticePrivacy policyEULACookiesOur Cookie Policy© Copyright 2026 CrowdSec All Rights Reserved

CrowdSec was notified on September 16, 2026, regarding a source code leak from its GitHub repository that occurred in May 2026, and the organization subsequently verified this report. The source code is structured into two distinct components: a private codebase and the codebase for the Free Open Source Software, specifically the Security Engine, which is intentionally public and therefore outside the scope of the security incident. The private repository contains sensitive elements, including the source code for the SaaS console, various AWS Cloud routines, connectors, and automations. While reports indicated a volume of around three hundred repositories, this number primarily reflects the code's internal subdivision rather than a specific measure of exposed volume. The organization explicitly stated that they do not confirm the leakage of any other files or internal development material, as all code is already published in these repositories.

The impact assessment indicated that no client data, login credentials, names, organizational details, or client logs were compromised, as CrowdSec does not store personally identifiable information or client logs. Consequently, the immediate risk to CrowdSec was limited to the organization itself. An internal investigation to locate any tokens, credentials, or sensitive information that could facilitate lateral movement found no such artifacts. The team suggested that although the exposed code held value, it could not immediately inflict harm on CrowdSec, given that the company's efficiency is dependent on its network effect and size, which code alone cannot replicate. Regular auditing of the SaaS source code was already in place, further suggesting that the leakage did not pose an imminent threat.

The investigation pointed toward the Tanstack compromise as the likely vector for the breach, drawing a parallel to the events seen in the Mistral AI case. It was hypothesized that a component within the Tanstack system was backdoored to extract an API key granting authorization to read the private codebase. This exploitation was only viable for a short duration in May 2026. In response to this vulnerability, CrowdSec immediately executed a comprehensive rotation of all necessary tokens and credentials to mitigate any ongoing threats. The CrowdSec team acknowledged the timely reporting by Fuites Infos.