Home / Aug 08, 2026 / Story
0
#8 The Hacker News general August 07, 2026 at 08:18 UTC

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

By [email protected] (The Hacker News)

AI Summary

Novee Security researchers demonstrated at Black Hat USA on August 5 that a GitHub issue opened by an unprivileged account was sufficient to execute code on the CI runners of Anthropic's (Claude Code) and Google's (Gemini CLI) own repositories, and to hijack the next agent run on OpenAI's infrastructure — all using default vendor configurations. The vulnerabilities were reported to all three vendors in late 2025 and early 2026 but remain unpatched, exposing the systemic prompt-injection risk in AI coding agents operating with CI/CD permissions.

Relevance score: 78.0/100

# More from August 08