MapRoulette (OpenStreetMap US) fixes years-old flaws that exposed users' OSM access tokens, API keys and emails, including an empty-key admin bypass and SQL injection; all credentials revoked, no sign of abuse in 29 days of logs
MapRoulette, an open-source tool that helps OpenStreetMap (OSM) contributors fix map problems, published a security incident report on 9 October 2026. Maintainer Jake Low of OpenStreetMap US found the flaws on 7 October, took the service offline for about 15 hours, revoked every credential that could have been exposed and shipped fixes in v4.11.0 and v4.11.1. Four main problems were found: public API and GraphQL responses included each user's full record, including the stored OSM access token (which can edit the map as that user), MapRoulette API key and email address (since April 2020); API keys saved in OSM user preferences could be read by any app granted the common 'read your user preferences' permission (since October 2022); sending an empty API key matched the never-set default 'super key' and granted administrator rights (since March 2017); and several endpoints allowed SQL injection (oldest from November 2019). The server and application logs, covering 8 September to 7 October 2026, showed no malicious use, but older abuse cannot be ruled out because the bugs are years old. OSM passwords were never at risk. Users must log in again, old API keys no longer work, affected users are being emailed, and anyone running a self-hosted MapRoulette above v2.0.3 must update, reset stored OAuth tokens and check admin accounts. Primary: OpenStreetMap community forum post by the maintainer.
- Product
- MapRoulette (maproulette.org and self-hosted instances)
- Versions
- self-hosted versions above v2.0.3; fixed in v4.11.0 / v4.11.1
- Exploited in Australia?
- unknown
- Patch to
- Users: log in again and be wary of emails asking for an OSM password. Self-hosters: upgrade to v4.11.1, reset stored OAuth tokens, review logs and superuser accounts.
Primary: OpenStreetMap Community — MapRoulette security incident, October 2026 (Jake Low, 9 Oct 2026)
