SECURITYTHE HACKER NEWS
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to hijack vulnerable public repositories by opening a single GitHub issue. The vulnerability could have enabled malicious code to be pushed into Anthropic's own action repository and downstream projects.
Related Signal
Adjacent reporting
- 'TrustFall' Exposes Claude Code Execution Risk
- GitHub fixes RCE flaw that gave access to millions of private repos
- CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
- Mythos Finds a Curl Vulnerability
- Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
- 'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues