Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

With just one open GitHub issue, a security researcher discovered a vulnerability in Anthropic’s Claude Code GitHub Action that allowed an attacker to take control of susceptible public repositories using it. A successful attack may have introduced malicious code into the action itself and onto the projects that pull it downstream because Anthropic’s own action repository employed the same approach.

After RyotaK of GMO Flatt Security revealed the core bypass to Anthropic in January, the company rectified it in four days and continued to strengthen it throughout the spring. The solutions are included in claude-code-action v1.0.94. Anthropic awarded a bug bounty and gave the problems a CVSS v4.0 rating of 7.8.

Claude Code GitHub Actions integrates Claude into CI/CD processes to perform slash commands, examine pull requests, apply labels, and prioritize issues. The code, problems, pull requests, discussions, and workflow files in a repository are all accessible to the workflow by default read more about Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *