// ClaudeHIGH
Novee Security disclosed critical vulnerabilities in Claude Code's GitHub Actions integration that enable remote code execution via prompt injection in CI/CD pipelines. The flaw allows attackers to bypass command validation through Git flag manipulation, leading to exfiltration of API keys (GITHUB_TOKEN, ANTHROPIC_API_KEY) and repository takeover. Anthropic assigned CVE-2026-54316 to the final vulnerability after multiple patch-and-bypass rounds. Similar flaws in Google's Gemini CLI (CVSS 10.0, GHSA-wpqr-6v78-jr5g) and OpenAI's Codex were also disclosed.
// Get alerts for Claude