2025 ClickUp — hardcoded Split.io key in public web assets; enterprise email & feature-flag exposure
Data compromised
Enterprise/government email strings embedded in feature-flag rules; internal roadmap/beta feature metadata
Technical writeup
Independent researchers reported that a hardcoded client-side API key for Split feature-flag services embedded in ClickUp’s marketing site allowed unauthenticated retrieval of experiment configuration and roughly 959 corporate or government email addresses present in targeting rules. Initial coordinated disclosure to ClickUp was dated January 17, 2025; follow-on trade coverage into 2026 described prolonged exposure and phishing/reconnaissance risk. The issue is categorized as an application misconfiguration rather than database exfiltration.
Root cause
Long-lived third-party SDK secret shipped in publicly downloadable JavaScript