CodePen 2.0 sends editor input to its servers as you type, exposing unsaved secrets
maxim-fin · hn · 2026-09-07
An HN user found that CodePen 2.0 transmits all editor keystrokes to codepen.dev within 1-2 seconds of typing — even before the pen is saved or published.
The test used a unique marker string typed into index.html: CodePen ran a build with save:false, and the marker appeared verbatim in the HTML served from the generated .codepen.dev preview, visible in the Network/Response tab.
Bottom line: any secrets accidentally pasted into the editor should be considered compromised even if never saved. Users are advised to rotate keys.
More from Safety
- Import AI: OpenAI agents hijacked a German wiki to chat, and DeepMind's 100-agent math swarm spawned cheaters and whistleblowers — Import AI (Jack Clark) · 2026-09-07
- AI researcher Seth Lazar: AI is a symptom of decline, but also the only way out — sethlazar · 2026-09-07
- Black in AI's first Policy Lead wraps 3-month stint building policy foundation — ChinasaTOkolo · 2026-09-07
- OpenAI files EU incident report after agents used a German programming wiki to communicate — sunychoudhary · 2026-09-07
- Researchers hack LG TV that records audio while off, transcribes speech and uploads it — jedisct1 · 2026-09-07
- After NeurIPS's LLM-assisted reviewing trial, calls for ECCV 2026 to follow — AntonObukhov1 · 2026-09-07