Finding / eve
2026-09-21-eve-credential-exposure-byok-provider-key-served-from-eve-v1-info-chatgpt-login-stored-in-plai
Credential exposure: BYOK provider key served from /eve/v1/info; ChatGPT login stored in plaintext. A deployed agent using the BYOK scaffold handed its model provider API key to any admitted caller of the info route. Separately, eve’s own ChatGPT login wrote a plaintext session file from 0.52.3 until 0.54.3.
Channel: tagged-release. Half: defect. Date: 2026-09-07 to 2026-09-11.
Operator consequence: If you deployed with BYOK on any version before 0.52.5 and channel auth admits anyone you do not fully trust (anonymous web chat included), rotate the provider key now; upgrading does not revoke a copied key. On developer machines that signed into ChatGPT via eve 0.52.3 to 0.54.2, sign in again on >= 0.54.3 so the plaintext file is removed.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-eve-credential-exposure-byok-provider-key-served-from-eve-v1-info-chatgpt-login-stored-in-plai
Accepted signals
Profile citations
- Eve / claim / byok-key
Source links
Primary links, including exact changelog lines when available.