Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic’s own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.

RyotaK of GMO

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

Next Post

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Related Posts
Total
0
Share