Mismanagement of a GitHub token allowed unauthorized access to Mercedes-Benz 's internal GitHub Enterprise Service , exposing the company's source code .

Mercedes-Benz, one of the most well-known automakers, uses software in its vehicles and services, including safety and control systems, infotainment, autonomous driving, and more.
On September 29, 2023, researchers at RedHunt Labs discovered a GitHub token in a public repository. It belonged to a Mercedez employee and was publicly available, meaning anyone could have access to the company's internal GitHub Enterprise Server
See also: ChatGPT: Leaks passwords from private chats
“ The GitHub token granted “unrestricted” and “unmonitored” access to the entire source code hosted on the Internal GitHub Enterprise Server ,” the researchers report
This led to the exposure of important repositories with a wealth of Mercedes-Benz copyrights , while the compromised information included access keys cloud, blueprints, design documents, SSO passwords, API keys and other important data.
Public exposure of such data poses a serious risk for Mercedes-Benz.
Source code leaks can allow competitors to gain insight into a company's technology and use it to their advantage, while cybercriminals could analyze the code to find vulnerabilities that they could exploit in vehicle systems.
Also, exposing API keys could lead to unauthorized access to data, service , and abuse of automotive infrastructure.
If the exposed repositories also contained customer data, then there could be legal consequences for the company, since there would also be a privacy.
RedHunt, with the help of TechCrunch, notified Mercedes-Benz of the token leak on January 22, 2024. Two days later, access was blocked.
See also: iPhone notifications leak users' personal data
BleepingComputer contacted Mercedes-Benz about the possibility of unauthorized access to the GitHub server. The response was as follows:
“We can confirm that the source code was published to a public GitHub repository due to human error. The token granted access to a specific number of repositories, but not to the entire source code hosted on the Internal GitHub Enterprise Server. We have revoked the relevant token and removed the public repository immediately. Customer data was not affected as our current analysis shows. We will continue to analyze this case in accordance with our usual procedures,” Mercedes-Benz said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What are the protective actions for future similar cases?
First, it is necessary to strengthen GitHub token management practices. This may include implementing stricter policies for token storage and renewal, as well as educating employees about the risks of careless token management.
Second, using multi-factor authentication (MFA) can provide an extra layer of security. MFA requires users to provide two or more verification methods to prove their identity, which can make it more difficult for unwanted users to gain access.
See also: Medusa Ransomware: From data leaks to multiple extortions
Third, implementing software security practices, such as continuous code scanning for vulnerabilities and the use of automated vulnerability, can help prevent similar incidents in the future.
Finally, creating a breach response plan can be crucial. This plan should include procedures for detecting, responding to, and recovering from a breach, as well as communicating with stakeholders.
Source: www.bleepingcomputer.com
