Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments
ID: c02265fb-a604-58bc-a62f-58b36280f3ed
STIX ID: report--c02265fb-a604-58bc-a62f-58b36280f3ed
Feed Name: Cyber Press
Researchers disclosed a ‘‘Comment and Control’’ prompt-injection technique that abuses standard GitHub features (PR titles, issue comments, hidden HTML) to manipulate AI-based developer tools (Claude Code Security Review, Google Gemini CLI Action, GitHub Copilot Agent). By embedding malicious instructions in repository content, attackers can cause these agents to execute commands and leak sensitive credentials (e.g., ANTHROPIC_API_KEY, GITHUB_TOKEN, GEMINI_API_KEY) into PR comments, issue threads, or repository commits; one vulnerability received a CVSS score of 9.4 and mitigations are only partial.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
