The Rust Security Response Team said Miri, run through cargo miri, saves all environment variables into the target/ folder. It called this not necessarily a vulnerability on its own. Exposure needs three things: secrets in the environment of the step that runs Miri, a cached target/ folder, and a cache that pull requests can read. Then anyone who has landed a change before could start a CI run to extract them, and push a second commit to cover their tracks. Predrag Gruevski of OpenAI reported it.
The short-term fix makes Miri keep only CARGO_* variables, except CARGO_*_TOKEN, and OUT_DIR. The team said the 2026-09-22 nightly will not have the problem, though the patch may not be on nightly yet. Its scan of GitHub repositories found 1 affected repository and 7 that look safe but should be careful. It has contacted those maintainers and called the scan likely imperfect. It did not say whether anyone has stolen secrets. It advises clearing caches and considering rotating secrets.
Miri is one case of a wider habit: giving secrets to a whole job, while tools assume they can write the environment to disk. Leaders can ask which CI jobs hold secrets, which caches pull requests can read, and how long logs and overwritten commits last. The team says they are deleted after a few months.