Rabbit AI exposed keys in code (Research)
ID: a4251296-cd82-5d41-84e2-8b6991f7d1f7
STIX ID: report--a4251296-cd82-5d41-84e2-8b6991f7d1f7
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-06-25
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers found hardcoded API keys in Rabbit AI's public code repository for multiple third-party services (ElevenLabs, Azure, Yelp, Google Maps, SendGrid); the exposed keys could allow attackers to access customer data, tamper AI outputs, render customer devices inoperable, and send emails from Rabbit's account, and the researchers demonstrated SendGrid abuse as proof-of-concept.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
