Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Code / repository leak
Reference · Pattern

Exposed .git directory on a production web server

Severity CriticalKind Code / repository leakEffort to fix TrivialUpdated 5 Aug 2026By LeakTrace
Definition

A production web server exposes its `.git/` directory over HTTP, allowing anyone to reconstruct the full source tree, including secrets committed to history.

What it is

When a codebase is deployed to a web server by cloning or pulling a git repository into the document root, the .git/ directory ends up publicly accessible unless the web server is explicitly configured to block it. Anyone who requests https://<domain>/.git/config and gets a 200 response can then use standard tooling to reconstruct the entire source tree, commit history, and any secrets that were ever committed and later removed.

Why it matters

Reconstructed source often contains database credentials, API keys, third-party integration tokens, and unsanitized customer data used in test fixtures. Even a "clean" current head can have secrets in history that a rotation swept from the working tree but not from the git objects.

How anyone can check it

curl -sI https://yourfirm.ca/.git/HEAD

A 200 response means the folder is readable from outside. It should be 403 or 404.

Remediation direction

Immediate: block .git/, .svn/, and .hg/ at the web server or CDN layer. Longer-term: deploy from a build artifact, not from a live git checkout. If any secret ever appeared in commit history, rotate that secret regardless of whether it appears in the current tree.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →