39 Exposed Algolia Admin Keys Threaten Major Open Source Projects

39 Exposed Algolia Admin Keys Threaten Major Open Source Projects

First seen 13 Mar 2026, 23:12 UTC News.YcombinatorReddit 72% similarity 70.5

Article Content

Browse articles
ThreatCluster

A cybersecurity researcher discovered 39 exposed Algolia admin API keys across various open source documentation sites. The keys, which were supposed to be read-only, had full permissions, allowing potential attackers to manipulate or delete indexed content. The researcher identified these keys by scraping approximately 15,000 documentation sites and analyzing GitHub repositories. Affected projects include popular ones like Assistant, KEDA, and vcluster, with some keys still active despite notifications sent to Algolia. The researcher reported the findings to Algolia, but as of today, no response has been received, and the keys remain active. This incident highlights a broader issue of misconfiguration in the use of Algolia's DocSearch service, which is intended to provide read-only access. The researcher warns that the actual number of exposed keys could be much higher, given the ease of finding them. Immediate action is recommended for organizations using Algolia's service to verify their API key configurations.

Key Points: • 39 Algolia admin API keys were found exposed on open source documentation sites. • The keys allowed full permissions, posing risks of data manipulation and deletion. • Most keys were discovered through frontend scraping, indicating widespread misconfiguration.

ThreatCluster AI

Timeline

2025-10-01
First exposed Algolia key reported on vuejs.org
2026-03-13
Researcher reports 39 exposed keys across documentation sites
2026-03-13
SUSE/Rancher acknowledges the report and rotates their key

Community

Browse all →