Vulnerabilità · 116 giorni fa
Una issue GitHub può diventare un path con capacità di scrittura verso un repo quando una azione CI si fida della cosa sbagliata. L’assunzione errata è che un nome che termina in [bot] significhi sicuro, e che il testo della issue sia solo input, non qualcosa che possa indirizzare un workflow a esporre secrets o modificare il codice.
2 fonti che coprono questa storia
Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog
Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions.
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
A flaw in Anthropic’s Claude Code GitHub Action allowed a malicious GitHub issue from a bot actor to trigger workflows and gain write access to repos.
Part of the PlainSec briefing for 2026-06-06