logo

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

ID: a075925d-528c-58e5-9c6c-dfc90b9bba53

STIX ID: report--a075925d-528c-58e5-9c6c-dfc90b9bba53

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: [email protected] (The Hacker News)

...
...

A security researcher found that Anthropic's Claude Code GitHub Action improperly trusted actors ending in "[bot]" and allowed agent-mode workflows to accept untrusted input, enabling prompt-injection attacks that exfiltrate environment secrets (notably the GitHub Actions OIDC credential). An attacker who replays those credentials can gain write access to repositories — including the action repo itself — creating a supply-chain risk; Anthropic patched the flaw in claude-code-action v1.0.94 and paid a bounty, and similar chains have already led to real token thefts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.