External Publication
Visit Post

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… June 4, 2026
Source
A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it. RyotaK of GMO

Discussion in the ATmosphere

Loading comments...