logo

Rabbit AI exposed keys in code (Research)

ID: a4251296-cd82-5d41-84e2-8b6991f7d1f7

STIX ID: report--a4251296-cd82-5d41-84e2-8b6991f7d1f7

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-06-25

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers found hardcoded API keys in Rabbit AI's public code repository for multiple third-party services (ElevenLabs, Azure, Yelp, Google Maps, SendGrid); the exposed keys could allow attackers to access customer data, tamper AI outputs, render customer devices inoperable, and send emails from Rabbit's account, and the researchers demonstrated SendGrid abuse as proof-of-concept.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.