Skip to main content
Mallory
Back to intelligence
build-pipeline-compromiseai-platform-securityleaked-secret-api-keywidely-deployed-product-advisory

Claude Code GitHub Action Flaws Exposed CI/CD Secrets and Enabled Repo Takeover

Updated 3d agoFirst seen Jun 4, 20262 sources

Researchers disclosed multiple security flaws in Anthropic’s Claude Code GitHub Action that could let attackers compromise public repositories and expose CI/CD secrets through a single malicious GitHub issue or other untrusted content. One issue, reported by RyotaK of GMO Flatt Security, stemmed from an authorization bypass that trusted any GitHub actor whose name ended in [bot], allowing attacker-controlled GitHub Apps to trigger workflows and inject malicious prompts. Anthropic said the bug could lead to disclosure of environment secrets, including credentials used to obtain OIDC tokens and Claude GitHub App installation tokens with write access, creating a path to repository takeover and broader supply-chain compromise.

Microsoft Threat Intelligence separately showed that Claude Code’s Read tool was not sandboxed like its Bash tool, enabling access to sensitive runner data such as /proc/self/environ and leakage of secrets including ANTHROPIC_API_KEY. In lab testing, Microsoft demonstrated prompt-injection attacks that bypassed model safeguards and GitHub secret scanning to exfiltrate credentials through logs, comments, or external channels. Anthropic fixed the authorization issue within days of disclosure and later added hardening in claude-code-action v1.0.94, while the /proc exposure was mitigated in Claude Code v2.1.128 by blocking access to sensitive procfs files; defenders were urged to treat AI-enabled CI/CD workflows processing untrusted issues, pull requests, and comments as high risk.

Share:
Claude Code GitHub Action Flaws Exposed CI/CD Secrets and Enabled Repo Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 5, 20264d ago

Microsoft publishes lab findings on Claude Code CI/CD secret exposure

Microsoft Threat Intelligence published research showing in lab conditions that prompt injection against Claude Code workflows could bypass model safeguards and GitHub secret scanning to leak CI/CD credentials. The company warned that AI workflows handling untrusted GitHub content and secrets should be treated as high risk.

Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog
Jun 4, 20264d ago

Researcher publicly discloses single-issue repository hijack vulnerability

A public disclosure described how one malicious GitHub issue could hijack vulnerable public repositories using Anthropic's Claude Code GitHub Action. The write-up said Anthropic assigned the flaw a CVSS v4.0 score of 7.8 and paid a bug bounty.

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

Anthropic fixes reported GitHub Action flaw within four days

After receiving the January report, Anthropic fixed the authorization-bypass issue within four days and later added further hardening in claude-code-action v1.0.94. The bug could have enabled repository compromise and exposure of CI/CD secrets from a single malicious GitHub issue.

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

Researcher reports Claude Code GitHub Action auth bypass to Anthropic

RyotaK of GMO Flatt Security reported a vulnerability in Anthropic's Claude Code GitHub Action in January. The flaw trusted any GitHub actor whose name ended in "[bot]," allowing attacker-controlled GitHub Apps to trigger the action with malicious issue content.

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
May 5, 20261mo ago

Anthropic mitigates Claude Code Read-tool secret exposure in v2.1.128

On 2026-05-05, Anthropic mitigated a separate Claude Code issue by blocking access to sensitive /proc files in version 2.1.128. Microsoft said the unsandboxed Read tool could expose runner secrets such as ANTHROPIC_API_KEY when AI agents processed untrusted GitHub content.

Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Claude Code GitHub Action Flaws Exposed CI/CD Secrets and Enabled Repo Takeover | Mallory