Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an unprivileged account was enough to access CI workflow secrets on Anthropic's and Google's coding-agent repositories, and to hijack subsequent agent runs on OpenAI's. Novee Security demonstrated the attacks at Black Hat USA on August 5.

A GitHub issue opened by an unprivileged account was enough to execute code on CI runners for Anthropic’s and Google’s coding-agent repositories, and hijack the next agent run on OpenAI’s. The attack, exploiting flaws in Claude Code and Gemini CLI, targeted each vendor’s agent in its default configuration. Novee Security presented the findings at Black Hat USA on August 5.