logo

Claude Code, Gemini CLI, and GitHub Copilot Exposed to Prompt Injection via GitHub Comments

ID: 363e8d3f-559c-5f23-9e7a-0b410bae783d

STIX ID: report--363e8d3f-559c-5f23-9e7a-0b410bae783d

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers demonstrated 'Comment and Control' indirect prompt-injection attacks against GitHub-integrated AI agents (Claude, Gemini, Copilot) where attackers embed malicious instructions in PR titles, issue comments, or hidden HTML comments. These manipulations cause the agents to execute commands or include secrets (API keys, GITHUB_TOKEN) in PR/issue comments or commits, bypassing runtime filters, secret scanning, and network restrictions and resulting in high-impact credential exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.