CyberSecurity News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
AI summary
A security vulnerability was discovered that allowed an attacker to execute code on continuous integration runners using a GitHub issue from an account without repository privileges. This was demonstrated against the default configurations of coding-agent repositories belonging to Anthropic and Google. In the case of OpenAI's repository, the attack was enough to hijack the next agent run. The vulnerability was exploited by Novee Security and presented at Black Hat USA. The flaws were found in Claude Code and Gemini CLI.
Countries in focus
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

