A Large-Scale Empirical Study of Secret Key Leakage in Hugging Face Spaces
Shaoxuan Yun, Yuchao Zhang, Zhikun Shi, Liu Wang, Yi Wang, Yu Bai
Abstract
Hugging Face Spaces (Spaces) has become a leading platform for hosting AI applications, offering developers seamless integration of Git-based repositories and out-of-the-box web service deployment. However, as its adoption continues to expand, security concerns have come to light. Recent reports have pointed to the issue of accidental exposure of sensitive information, such as API tokens and database credentials, within Spaces-hosted code. Despite these concerns, the research community still lacks a comprehensive understanding of the scope and impact of these security risks. To bridge this gap, we present the first large-scale and systematic empirical study to quantify the extent of secret key leakage in Spaces. We begin by compiling a comprehensive dataset of 313,647 public Spaces repositories created between March 2022 and December 2024. To detect exposed secret keys, we introduce Secret Reviewer, an advanced framework that combines static analysis and Large Language Model (LLM)-assisted detection to identify leaked credentials. Applying Secret Reviewer, we identified 9,149 with secret keys leakage vulnerabilities and 11,557 unique keys—76% of which from leading AI service providers such as OpenAI and Groq. Our findings indicate that 30% of leaks were embedded in commit histories, and over 1,000 non-code files contained sensitive data. Further validation revealed that 30% of detected keys remained active, including 140 valid database credentials and 50% of access tokens with write permissions, underscoring significant security risks. Our study sheds light on critical security challenges in AI platform ecosystems and advocates for stronger security practices to mitigate these risks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9ec3daa5-f352-4470-82a8-d2a0acaf51f5Related papers
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 130 citations
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu et al.CCS 2026 · 1 citation
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
- Secrets Unlocked: Evaluating LLMs for Secrets Detection in Android AppsMarco Alecci, Jordan Samhi, Tegawendé F. Bissyandé, Jacques KleinISSTA 2026
- Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code RepositoriesAlexander Krause, Jan H. Klemmer, Nicolas Huaman, Dominik Wermke et al.USENIX Security 2023
