Craft
A public API repo on a Gogs server leaks an unsanitised eval() in the brew-ABV check, and a second commit leaks the API creds needed to reach it, so a JSON field turns into RCE inside a Docker container. DB creds from settings.py dump the user table, Gilfoyle reused his password on Gogs, and the same password again decrypts an SSH key from a private repo. His .vault-token is scoped to a HashiCorp Vault root_otp SSH role, so vault ssh just hands me a one-time root password.