As cited
Copy frozen at (site build).
vulnerabilities
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Novee Security discovered critical flaws in Claude Code, Gemini CLI, and OpenAI's agent repositories that allowed unauthenticated attackers to execute code on CI runners or hijack agent runs through GitHub issues opened by unprivileged accounts. The researchers demonstrated the attacks against default vendor configurations at Black Hat USA on August 5.
Why it matters: Development teams using these AI coding agents or running them in CI pipelines are exposed to arbitrary code execution and secret theft. Practitioners should immediately review CI configurations for these agents and restrict webhook permissions until vendors patch the issues.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Novee Security discovered vulnerabilities in Claude Code and Gemini CLI that allow unauthenticated GitHub issue creation to trigger code execution in CI workflows with access to repository secrets. The researchers demonstrated arbitrary code execution on Anthropic and Google's own repositories, and the ability to hijack OpenAI's agent runs, using default vendor configurations.
Why it matters: DevOps and platform teams using these coding agents in CI/CD pipelines are exposed to unauthorized code execution and secret theft; verify your GitHub Actions configurations immediately to restrict which triggers execute privileged workflows.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Novee Security discovered vulnerabilities in Claude Code and Gemini CLI that allow unauthenticated GitHub issue creation to trigger code execution in CI workflows with access to repository secrets. The researchers demonstrated arbitrary code execution on Anthropic and Google's own repositories, and the ability to hijack OpenAI's agent runs, using default vendor configurations.
Why it matters: DevOps and platform teams using these coding agents in CI/CD pipelines are exposed to unauthorized code execution and secret theft; verify your GitHub Actions configurations immediately to restrict which triggers execute privileged workflows.
- Source published
- First seen by Cybersecurity Tracker