ClickUp Data Leak Exposes Enterprise Emails for Over a Year
ID: ac18abbd-7cf5-513d-b41f-e40ae42b2f97
STIX ID: report--ac18abbd-7cf5-513d-b41f-e40ae42b2f97
Feed Name: TechRepublic Security
Threat Score
A hardcoded third-party API key embedded in ClickUp's public JavaScript allowed unauthenticated access to a backend endpoint, exposing 959 corporate and government email addresses and 3,165 internal feature flags for more than a year; the prolonged exposure raises the risk of targeted phishing, credential stuffing, and intelligence gathering and underscores the need for stricter API key hygiene, access controls, and third-party SaaS security practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
