news.mlab.sh
Back to the feed
vulnerability

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

High
Image: The Hacker News
Summary

Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed command injection, while Claude Code exploited a public download counter to leak API keys. Both have been patched, but the initial discovery involved a public reproduction lab demonstrating the exploit. The vulnerabilities stemmed from flaws in how the CI/CD systems handled untrusted input and tool allowlists.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.