ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants
ID: 1b5f9a7a-6432-57c1-a448-c027f2ac7828
STIX ID: report--1b5f9a7a-6432-57c1-a448-c027f2ac7828
Feed Name: cybersecurityNews.com
Threat Score
A hardcoded third-party API key in ClickUp's publicly served JavaScript exposed 959 corporate and government email addresses and 3,165 internal feature flags; the issue was reported on January 17, 2025 but the key remained unrotated as of April 2026, leaving employees from major organisations and government entities exposed to phishing, social engineering, and intelligence collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
