Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaw in GitHub Action Exposes Repositories

Security Flaw in GitHub Action Exposes Repositories

Posted on June 4, 2026 By CWS

In January 2026, a critical vulnerability was discovered in Anthropic’s Claude Code GitHub Action by RyotaK from GMO Flatt Security. This flaw allowed attackers to hijack public repositories using the action by merely opening a GitHub issue. The potential damage included injecting malicious code into the action itself, affecting all downstream projects utilizing it.

Anthropic responded swiftly to the report, implementing a fix within four days and further strengthening security measures in subsequent months. The vulnerability, rated 7.8 on the CVSS v4.0 scale, was addressed with the release of claude-code-action v1.0.94. The company also rewarded the researcher with a bug bounty for his contribution.

Understanding the GitHub Action Flaw

Claude Code GitHub Actions integrates into CI/CD pipelines to manage issues, apply labels, review pull requests, and execute commands. The default settings grant extensive read and write permissions across a repository’s code, issues, pull requests, and workflow files. Ideally, only users with write access should trigger these workflows.

However, a loophole existed that allowed any actor with a name ending in [bot] to bypass these restrictions. This assumption about the trustworthiness of GitHub Apps led to vulnerabilities, as anyone could create a GitHub App, install it on their repository, and leverage its token to interact with public repositories. The absence of adequate checks in agent mode left the system open to exploitation.

Exploitation and Implications

Attackers could utilize indirect prompt injection, a method of embedding instructions in content intended for AI reading. RyotaK demonstrated how an attacker could use this technique to exploit the action, gaining access to sensitive environment variables and credentials. Particularly valuable were the credentials used to request an OIDC token, enabling attackers to gain write access to a repository’s code and workflows.

Moreover, Anthropic’s own example workflows contained risky settings, allowing non-write users to trigger actions. This oversight led to the risk of data leakage through publicly visible task summaries. The issue was compounded by repositories copying these flawed examples, inadvertently inheriting the security weaknesses.

Preventive Measures and Future Outlook

To mitigate this risk, users are advised to update to claude-code-action v1.0.94 or later and audit workflows to ensure that only trusted users can trigger actions. It’s crucial to limit the exposure of sensitive data and remove unnecessary permissions that could facilitate data exfiltration.

While this particular vulnerability has not been publicly exploited against live targets, the potential for abuse remains significant. RyotaK continues to identify and report security loopholes in AI coding agents, highlighting the persistent challenge of addressing prompt injection vulnerabilities.

The incident underscores the need for robust security practices and vigilance in managing permissions and workflows within software development environments. As AI integration into development processes grows, maintaining security will be a continuous and evolving challenge.

The Hacker News Tags:AI, Anthropic, Claude Code, Cybersecurity, GitHub, GitHub actions, RyotaK, Security, Software Security, Vulnerability

Post navigation

Previous Post: TA4922 Cyber Group Expands Global Malware Campaigns
Next Post: Offroad Secures $7M Funding to Address Identity Risks

Related Posts

Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors The Hacker News
Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More The Hacker News
Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero The Hacker News
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates The Hacker News
Can your SOC Save You? Can your SOC Save You? The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Offroad Secures $7M Funding to Address Identity Risks
  • Security Flaw in GitHub Action Exposes Repositories
  • TA4922 Cyber Group Expands Global Malware Campaigns
  • Third-Party Risk Management: Addressing Program Challenges
  • AI Agents and Cyber Threats: Latest Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Offroad Secures $7M Funding to Address Identity Risks
  • Security Flaw in GitHub Action Exposes Repositories
  • TA4922 Cyber Group Expands Global Malware Campaigns
  • Third-Party Risk Management: Addressing Program Challenges
  • AI Agents and Cyber Threats: Latest Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark