← ClickUp

2025 ClickUp — hardcoded Split.io key in public web assets; enterprise email & feature-flag exposure

2025 959 records affected Share on X

Data compromised

Enterprise/government email strings embedded in feature-flag rules; internal roadmap/beta feature metadata

Technical writeup

Independent researchers reported that a hardcoded client-side API key for Split feature-flag services embedded in ClickUp’s marketing site allowed unauthenticated retrieval of experiment configuration and roughly 959 corporate or government email addresses present in targeting rules. Initial coordinated disclosure to ClickUp was dated January 17, 2025; follow-on trade coverage into 2026 described prolonged exposure and phishing/reconnaissance risk. The issue is categorized as an application misconfiguration rather than database exfiltration.

Root cause

Long-lived third-party SDK secret shipped in publicly downloadable JavaScript

References