A Secret From the Second Commit, Found Five Months Later: Finding a Hardcoded JWT Secret in a Security Audit
A security review of MockEvalio found admin auth silently broken, a cross-tenant data leak, and a hardcoded key that traced straight back to the project's second commit, five months earlier.
Aug 25, 2026
5 min read