ยท 3 days agoยท Dev.to
Critical GitHub Vulnerability Exposes Workflow Secrets via Claude Code
A security researcher showed that a GitHub PR title, issue body, or comment could become a prompt injection that hijacks Claude Code (and Gemini CLI, and GitHub Copilot) running in GitHub Actions, then makes it dump the workflow's secrets. Anthropic rated its variant CVSS 9.4 Critical. There is no m
#github#claude code#ci/cd#security vulnerability#india tech