CVE-2025-23040 - Credential Leak in GitHub Desktop GitHub Desktop (< 3.4.12) is vulnerable to an attack that allows exfiltration of credentials via malicious remote URLs. An attacker can convince a user to clone a manipulated repository to obtain username and OAuth token.