A critical vulnerability, allowing remote code execution (RCE), was found in CodeRabbit and provided unauthorized access to over a million code repositories (including private ones).

The vulnerability, discovered in December 2024 and responsibly disclosed in January 2025, exploited the static analysis tool integration to leak sensitive API credentials and allow write access to GitHub repositories via the compromised GitHub App private key.
CodeRabbit, the most popular AI-assisted app on the GitHub Marketplace, quickly fixed the issue by disabling the vulnerable Rubocop integration and rotating all potentially compromised credentials.
See also: Chrome vulnerability allows malicious code execution
CodeRabbit: Rubocop Vulnerability
The vulnerability focused on CodeRabbit's integration with Rubocop, a Ruby static analyzer that processes .rubocop.yml configuration files submitted via pull requests. The researchers discovered that Rubocop's extension mechanism could be exploited by cybercriminals by creating a malicious configuration containing the ./ext.rb directive. This allows arbitrary Ruby code to be executed when CodeRabbit processes the pull request.
The exploitation process involved creating a repository with three key files: a configuration file .rubocop.yml, a malicious extension file ext.rb (with payload code), and a fake Ruby file to trigger the execution of Rubocop. The payload exploited Ruby's environment variable access capabilities, specifically ENV.to_h, to extract sensitive data via HTTP POST requests to a server controlled by the attacker.

The successful exploit allowed extensive access to CodeRabbit’s production infrastructure, including critical API keys for services such as Anthropic, OpenAI, Langchain, and Pinecone. PostgreSQL database credentials and encryption keys were also affected. The most significant breach involved the GITHUB_APP_PEM_FILE environment variable that contained CodeRabbit’s GitHub App private key, which provided write access to all repositories where users had installed the CodeRabbit app.
See also: SAP NetWeaver: Public Exploit for chained vulnerabilities
This private key allowed the attackers to create access tokens with extensive permissions, including: read/write content, read metadata, write pull requests, and platform-wide repository management capabilities. Using the PyGitHub and the exposed app ID, the attackers were able to record installs, record accessible repositories, and clone private repositories, including CodeRabbit's internal repositories such as coderabbitai/mono and coderabbitai/pr-reviewer-saas.
How CodeRabbit dealt with the situation
The company completely disabled Rubocop processing while developing a permanent solution and rotating all potentially compromised credentials and API keys. The permanent solution included moving Rubocop and other external tools to CodeRabbit’s secure sandbox environment.
Additional security enhancements included comprehensive system audits, automated sandbox enforcement mechanisms, and hardened deployment portals to prevent similar incidents.
This particular vulnerability in CodeRabbit is one of the most prominent examples of how even a seemingly “safe” feature – such as the integration of static analysis tools – can become a serious entry point for cyberattacks. This incident is a reminder of the fragile nature of the software supply chain, where a single security hole can expose millions of code repositories and put high-value data at risk.
See also: CISA: Warns of vulnerability in Trend Micro Apex One
Of particular concern is the access provided by the compromised GitHub App private key. In the wrong hands, such a key could provide write access to large organizations’ repositories, paving the way for supply chain attacks via malicious commits or backdoors in the code. This could have huge consequences, not only for CodeRabbit itself but also for any business that relies on its services.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company's quick response was necessary to limit the damage. However, the incident highlights the need for a zero trust architecture and strong isolation of third-party tools. Companies that integrate external plugins or tools should run them in fully isolated environments, with minimal permissions and strict behavioral monitoring.
In an era where AI-assisted development and the widespread use of marketplaces are becoming the norm, incidents like CodeRabbit’s show that security must be treated as a primary concern. It’s not enough to fix vulnerabilities after the fact – proactive planning and continuous evaluation of interactions with external services are needed.
