<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk" -->

---
title: Cypress Security Incident: Status and Response | daily.dev
description: Cypress reported a security incident affecting Metabase, a third-party analytics tool used internally. Metabase disclosed that an attacker exploited a...
canonical: https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cypress Security Incident: Status and Response | daily.dev
og:description: Cypress reported a security incident affecting Metabase, a third-party analytics tool used internally. Metabase disclosed that an attacker exploited a...
og:url: https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk
og:image: https://api.daily.dev/og/posts/oN02SP6jK.png
og:image:alt: Cypress Security Incident: Status and Response
og:image:width: 1200
og:image:height: 630
og:locale: en
---

[cypress](https://daily.dev/sources/cypress)

[Read post](https://api.daily.dev/r/oN02SP6jK)

# [Cypress Security Incident: Status and Response](https://api.daily.dev/r/oN02SP6jK "Go to post")

Cypress reported a security incident affecting Metabase, a third-party analytics tool used internally. Metabase disclosed that an attacker exploited a previously unknown vulnerability in its cloud platform on July 31, 2026, gaining access to a subset of data including business/account data, repository and build metadata, and in some cases tokens and test data. Cypress Cloud test run operation, record keys, account passwords, and billing information were unaffected. Cypress rotated database credentials, revoked GitHub OAuth tokens used for sign-in, audited access logs, and engaged an independent forensic firm. Recommendations for affected users include rotating any secrets placed in build parameters or test data, rotating hardcoded long-lived version control tokens used in CI, reviewing version control access logs from July 31, 2026, and watching for phishing attempts.

[#security](/tags/security "Check all #security posts")[#testing](/tags/testing "Check all #testing posts")[#cypress](/tags/cypress "Check all #cypress posts")

Aug 13•8m read time•From [cypress.io](https://api.daily.dev/r/oN02SP6jK "cypress.io")

[![Post cover image](https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb1bc5e408f8cd3b3876bc79cf635b9a?_a=AQAEuop)](https://api.daily.dev/r/oN02SP6jK "Go to post")

Table of contents

[What happened](https://api.daily.dev/r/oN02SP6jK?a=what-happened "What happened")[What we have done to protect your data](https://api.daily.dev/r/oN02SP6jK?a=what-we-have-done-to-protect-your-data "What we have done to protect your data")[What information was involved](https://api.daily.dev/r/oN02SP6jK?a=what-information-was-involved "What information was involved")[What we recommend you do](https://api.daily.dev/r/oN02SP6jK?a=what-we-recommend-you-do "What we recommend you do")[Additional security recommendations](https://api.daily.dev/r/oN02SP6jK?a=additional-security-recommendations "Additional security recommendations")[What we are doing next](https://api.daily.dev/r/oN02SP6jK?a=what-we-are-doing-next "What we are doing next")[Frequently asked questions](https://api.daily.dev/r/oN02SP6jK?a=frequently-asked-questions "Frequently asked questions")

Questions this post answers

What happened in the Cypress Metabase security incident and what data was exposed?

An attacker exploited a previously unknown vulnerability in Metabase's cloud platform on July 31, 2026, gaining access to a subset of Cypress's Metabase Cloud instance data. Exposed information included limited business and account data, repository and build metadata, and in some cases tokens and test data. Cypress test run operation and results, record keys, account passwords, and billing payment information were not affected. Teams tracking third-party vendor breaches affecting their CI pipeline can follow security incident coverage on daily.dev.

Do I need to rotate my Cypress record keys after the Metabase security incident?

No, Cypress record keys were not affected by the Metabase incident and rotation is not required, though it can be done out of caution if preferred. GitHub OAuth tokens used for Cypress Cloud sign-in were revoked as a precaution, so users may need to sign in again, but no other action is needed for that either. daily.dev helps developers stay on top of vendor security notices before deciding what to rotate.

Should I rotate long-lived version control tokens hardcoded in my CI configuration?

Yes, if a long-lived access token was hardcoded into a repository's remote URL used by CI to clone source code, it should be rotated with the version control provider immediately following exposure. Short-lived tokens generated per CI run expire automatically and require no action. Reviewing version control access logs from July 31, 2026 onward is also recommended to check for unauthorized access. daily.dev surfaces incident guidance for developers hardening CI token practices after a breach.

11 Impressions

Comment

Bookmark

Copy

![Placeholder image for anonymous user](https://media.daily.dev/image/upload/s--qsFuKGv_--/t_logo,f_auto/public/noProfile)Share your thoughtsPost

[![cypress's image](https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/ad08f015b27b4d42a287d745bbb9c722)](https://daily.dev/sources/cypress)

[cypress](https://daily.dev/sources/cypress "https://daily.dev/sources/cypress")

Cypress's platform is a resource for developers and QA engineers, offering insights into end-to-end ... Read more

135 Followers

•

245 Upvotes

#### Would you recommend this post?

Copy link

WhatsApp

Facebook

X

New Squad

Copy linkShare with your friends

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cypress Security Incident: Status and Response","url":"https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk"},"datePublished":"2026-08-13T01:03:30.586Z","dateModified":"2026-08-13T02:30:42.523Z","description":"Cypress reported a security incident affecting Metabase, a third-party analytics tool used internally. Metabase disclosed that an attacker exploited a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb1bc5e408f8cd3b3876bc79cf635b9a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb1bc5e408f8cd3b3876bc79cf635b9a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"cypress","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"cypress","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/ad08f015b27b4d42a287d745bbb9c722","url":"https://daily.dev/sources/cypress"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,testing,cypress","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"cypress","item":"https://daily.dev/sources/cypress"},{"@type":"ListItem","position":3,"name":"Cypress Security Incident: Status and Response"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cypress-security-incident-status-and-response-on02sp6jk#faq","mainEntity":[{"@type":"Question","name":"What happened in the Cypress Metabase security incident and what data was exposed?","acceptedAnswer":{"@type":"Answer","text":"An attacker exploited a previously unknown vulnerability in Metabase's cloud platform on July 31, 2026, gaining access to a subset of Cypress's Metabase Cloud instance data. Exposed information included limited business and account data, repository and build metadata, and in some cases tokens and test data. Cypress test run operation and results, record keys, account passwords, and billing payment information were not affected. Teams tracking third-party vendor breaches affecting their CI pipeline can follow security incident coverage on daily.dev."}},{"@type":"Question","name":"Do I need to rotate my Cypress record keys after the Metabase security incident?","acceptedAnswer":{"@type":"Answer","text":"No, Cypress record keys were not affected by the Metabase incident and rotation is not required, though it can be done out of caution if preferred. GitHub OAuth tokens used for Cypress Cloud sign-in were revoked as a precaution, so users may need to sign in again, but no other action is needed for that either. daily.dev helps developers stay on top of vendor security notices before deciding what to rotate."}},{"@type":"Question","name":"Should I rotate long-lived version control tokens hardcoded in my CI configuration?","acceptedAnswer":{"@type":"Answer","text":"Yes, if a long-lived access token was hardcoded into a repository's remote URL used by CI to clone source code, it should be rotated with the version control provider immediately following exposure. Short-lived tokens generated per CI run expire automatically and require no action. Reviewing version control access logs from July 31, 2026 onward is also recommended to check for unauthorized access. daily.dev surfaces incident guidance for developers hardening CI token practices after a breach."}}]}
```

