Skip to content

Vulnerabilities in Claude Code and Gemini CLI Allow Access to CI Secrets via GitHub Issues

Bottom line: A GitHub issue from an account with no permissions was enough to exploit vulnerabilities in Claude Code and Gemini CLI to execute code on CI runners with access to secrets, and at OpenAI it allowed compromising the next agent run.

Security researchers from Novee Security have shown that a simple GitHub issue, created by an account without repository permissions, was sufficient to execute code on the CI runners behind Anthropic’s and Google’s AI coding agents. At OpenAI, the same attack chain was enough to take over the next agent run.

The researchers tested the attacks against the default configuration in which the providers ship their coding agents. Affected are Claude Code from Anthropic and Gemini CLI from Google, whose respective repositories could be manipulated via GitHub issues: an account without any write or repository permissions opened an issue that was sufficient to execute code on the projects’ CI runners. At OpenAI, the same technique worked differently, but it could still compromise the agent’s next run there. The findings were presented on August 5 at Black Hat USA in Las Vegas.

For CISOs, the relevant point is that no zero-day exploits in the classic sense were needed here; instead, a weakness in the interplay between AI coding agents, CI/CD pipelines and publicly accessible interaction channels such as GitHub issues was exploited. Attackers required no privileged access to the repository whatsoever to gain execution rights on CI runners, which typically hold secrets, credentials and deployment permissions. This particularly affects organizations that use Claude Code, Gemini CLI or comparable coding agents in their own development pipelines with default configuration.

The reporting does not provide any information on specific CVE IDs, affected version numbers, or patches already released by the three providers. CISOs should review whether the use of AI coding agents in CI/CD environments allows triggers from public or low-privilege interactions such as issues, pull requests or comments to actually result in execution rights on runners with access to secrets, and whether the respective providers’ default configuration already restricts this.


Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: