Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Source: The Hacker News

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run.

Novee Security ran the attack against each vendor’s agent in the con


Read original