Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
ID: a075925d-528c-58e5-9c6c-dfc90b9bba53
STIX ID: report--a075925d-528c-58e5-9c6c-dfc90b9bba53
Feed Name: The Hacker News
A security researcher found that Anthropic's Claude Code GitHub Action improperly trusted actors ending in "[bot]" and allowed agent-mode workflows to accept untrusted input, enabling prompt-injection attacks that exfiltrate environment secrets (notably the GitHub Actions OIDC credential). An attacker who replays those credentials can gain write access to repositories — including the action repo itself — creating a supply-chain risk; Anthropic patched the flaw in claude-code-action v1.0.94 and paid a bounty, and similar chains have already led to real token thefts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
