Claude Code GitHub Action Vulnerability Patched After Microsoft Discovers Credential Theft Risk

According to Microsoft researchers, a vulnerability in Anthropic's Claude Code GitHub Action discovered on Friday could allow attackers to steal credentials from development pipelines through prompt injection attacks. The flaw let adversaries hide malicious instructions in GitHub issues, pull requests, or comments to manipulate the AI agent into exposing API keys and sensitive data. Anthropic patched the vulnerability on May 5 with version 2.1.128 after Microsoft disclosed the issue through HackerOne on April 29.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments