logo

Claude Code GitHub Actions Flaw Exposes Repositories to Full Compromise

ID: 537a53d1-b6d7-5633-af23-b8e521c012f9

STIX ID: report--537a53d1-b6d7-5633-af23-b8e521c012f9

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Divya

...
...

A critical vulnerability in Anthropic’s Claude Code GitHub Actions allowed attackers to bypass permission validation via malicious GitHub Apps and crafted issues, enabling prompt-injection-style payloads that exfiltrated secrets (including OIDC credentials) and could lead to full repository compromise and downstream supply-chain attacks; Anthropic released fixes (v1.0.94) and researchers reported active exploitation with a CVSS score of 7.8.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.