Coders Beware: Major Code Formatting Sites Apparently Exposing Huge Amounts of User Data



  • WatchTowr discovered that JSONFormatter and CodeBeautify exposed sensitive data via unprotected “Recent Links” features
  • Researchers mined years of raw data and discovered credentials, private keys, API tokens, and PII from critical industries.
  • Criminals are already investigating the flaw, highlighting the risks of uploading sensitive code to public formatting sites.

Some major code formatting sites are exposing sensitive and identifiable information that could put countless organizations, including government and critical infrastructure organizations, at risk, experts have warned.

Cybersecurity researchers WatchTowr analyzed JSONFormatter and CodeBeautify, services where users can submit code or data (most commonly JSON) to be formatted, validated, and “beautified” to make it easier to read and debug.



Leave a Comment

Your email address will not be published. Required fields are marked *