Stripe API key found in JavaScript bundle
A Stripe secret key (sk_live_*) was found in the client-side JavaScript bundle, exposing payment processing credentials.
CWE
CWE-798
CVE
N/A
OWASP
N/A
CVSS Score
8.2
Source
Secrets
Category
Exposed API Key
Exploitability
Exploitable
Detected
2026-05-30 19:02
Code Location
src/public/js/checkout.js:142// No code snippet available for this finding.
AI Explanation
This finding was detected by automated scanning. Use the Security Copilot for a detailed AI-powered explanation of this vulnerability, including attack vectors and business impact analysis.
Remediation Suggestion
Review the finding details and apply the recommended fix. Use the Security Copilot for AI-generated remediation code specific to your technology stack and coding patterns.
Related Findings
| Severity | Title | CWE | Status |
|---|---|---|---|
Critical |
AWS Access Key exposed in configuration file | CWE-798 | Open |
Change Status