Finding #100
High
Open
Stripe API key found in JavaScript bundle

A Stripe secret key (sk_live_*) was found in the client-side JavaScript bundle, exposing payment processing credentials.


CWE

CWE-798

CVE

N/A

OWASP

N/A

CVSS Score

8.2

Source
Secrets
Category

Exposed API Key

Exploitability

Exploitable

Detected

2026-05-30 19:02

Code Location

src/public/js/checkout.js:142
// No code snippet available for this finding.

AI Explanation

This finding was detected by automated scanning. Use the Security Copilot for a detailed AI-powered explanation of this vulnerability, including attack vectors and business impact analysis.

Remediation Suggestion

Review the finding details and apply the recommended fix. Use the Security Copilot for AI-generated remediation code specific to your technology stack and coding patterns.

Related Findings

Severity Title CWE Status
Critical
AWS Access Key exposed in configuration file CWE-798
Open

Change Status

🛡️ Security AI