High severity Vulnerability

Exposed Source Control Metadata

A reachable .git directory hands an attacker the entire repository history, including rotated secrets.

Overview

When /.git/ is served statically, tools can reconstruct the working tree commit by commit.\nThe damage is rarely the source itself: it is the database passwords, API keys and tokens that were committed and later "removed", which remain in history forever.\nThe same applies to .env backups, .DS_Store, composer.lock leakage and .svn folders.

Indicators of Compromise

Signals that suggest this is present on a system.

  • /.git/HEAD returning "ref: refs/heads"
  • .git/config served with 200 OK
  • Editor or backup files reachable publicly

Controls that stop it

  • Apply Least Privilege Everywhere

    Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used