TRB-025v1.0.0 · envfile_sensitive_values
Envfile sensitive values
Envfile sensitive values identifies credential material is exposed or relies on an insufficiently protected secret.
CWE mapping
CWE-798insufficient recognition
Assurance
The analyzer verified the reported construct is present in the supplied input.
Conditional: Impact depends on how the destination parser, runtime, or deployment is configured.
Inert example
Displayed as text only. tryb does not execute this example.
API_TOKEN=example-onlyRemediation
inspect-context. The observed property needs destination-specific policy before an automatic rewrite is safe.
Verify: Inspect the actual consumer and encode the intended acceptance rule in a test.
What to verify next
Confirm the exact production parser and security settings before treating this as exploitable.