Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments
ID: dc07fddf-769e-5416-b703-bc4938f37e9b
STIX ID: report--dc07fddf-769e-5416-b703-bc4938f37e9b
Feed Name: cybersecurityNews.com
A newly identified cross-vendor prompt-injection class called "Comment and Control" weaponizes GitHub pull-request titles, issue bodies, and comments to proactively trigger AI coding agents (Anthropic Claude, Google Gemini CLI, GitHub Copilot Agent) via standard Actions events and coerce them to execute commands or reveal secrets (API keys, GITHUB_TOKEN, Copilot tokens) directly into PR comments, issue comments, or git commits. Researchers demonstrated multiple technical bypasses of environment filtering, secret scanning, and network restrictions, rated a critical CVSS for at least one finding, and recommend strict tool allowlists, least-privilege secrets, human approval gates, and auditing of AI integrations as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
