logo

Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments

ID: c02265fb-a604-58bc-a62f-58b36280f3ed

STIX ID: report--c02265fb-a604-58bc-a62f-58b36280f3ed

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: AnuPriya

...
...

Researchers disclosed a ‘‘Comment and Control’’ prompt-injection technique that abuses standard GitHub features (PR titles, issue comments, hidden HTML) to manipulate AI-based developer tools (Claude Code Security Review, Google Gemini CLI Action, GitHub Copilot Agent). By embedding malicious instructions in repository content, attackers can cause these agents to execute commands and leak sensitive credentials (e.g., ANTHROPIC_API_KEY, GITHUB_TOKEN, GEMINI_API_KEY) into PR comments, issue threads, or repository commits; one vulnerability received a CVSS score of 9.4 and mitigations are only partial.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.