Severity

high

Exposure

4/5

Date of incident

March 20, 2023
OpenAI Redis exposed API keys

confirmed

Tier -

A

Provider bug exposed API keys — agents with embedded keys lacked ingress vault boundary.
What Happened
Cache misconfiguration exposed chat session metadata and active API keys to unauthorized users for a short window; teams with agents embedding keys in IDE and MCP configs faced rotation and blast-radius review.
Sumarry
OpenAI disclosed a Redis cache bug that briefly exposed active API keys and limited user data — relevant to any agent stack using OpenAI APIs.
Detect
Key rotation + NHIM-014 on env patterns
What Happened
Trust Vault in-cluster hydrate — never raw keys in agent context
Blekline //
In-cluster Trust Vault — keys never in model context
Without agent boundary //
Rotate keys after vendor disclosure — no prevent at ingress

Looking to integrate AI company-wide?