Evidence record / eve

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-09-21-eve-credential-exposure-byok-provider-key-served-from-eve-v1-info-chatgpt-login-stored-in-plai

Credential exposure: BYOK provider key served from /eve/v1/info; ChatGPT login stored in plaintext. A deployed agent using the BYOK scaffold handed its model provider API key to any admitted caller of the info route. Separately, eve’s own ChatGPT login wrote a plaintext session file from 0.52.3 until 0.54.3.

Channel: tagged-release. Half: defect. Date: 2026-09-07 to 2026-09-11.

Operator consequence: If you deployed with BYOK on any version before 0.52.5 and channel auth admits anyone you do not fully trust (anonymous web chat included), rotate the provider key now; upgrading does not revoke a copied key. On developer machines that signed into ChatGPT via eve 0.52.3 to 0.54.2, sign in again on >= 0.54.3 so the plaintext file is removed.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-eve-credential-exposure-byok-provider-key-served-from-eve-v1-info-chatgpt-login-stored-in-plai

Profile citations

  • Eve / claim / byok-key

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact