logo

ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

ID: 1b5f9a7a-6432-57c1-a448-c027f2ac7828

STIX ID: report--1b5f9a7a-6432-57c1-a448-c027f2ac7828

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Guru Baran

...
...

A hardcoded third-party API key in ClickUp's publicly served JavaScript exposed 959 corporate and government email addresses and 3,165 internal feature flags; the issue was reported on January 17, 2025 but the key remained unrotated as of April 2026, leaving employees from major organisations and government entities exposed to phishing, social engineering, and intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.