MapRoulette discovered multiple security vulnerabilities in October 2026 that exposed user email addresses and OSM access tokens, potentially allowing attackers to impersonate users and edit OpenStreetMap. Maintainer Jake Low took the service offline, revoked compromised credentials, and deployed patches; server logs showed no evidence of exploitation, though the bugs existed for years.