✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved

GitHub Issue Exploited Claude Code, Gemini CLI, Codex CI

By The Hacker News · Summarized & edited by · 2026-08-07
GitHub Issue Exploited Claude Code, Gemini CLI, Codex CI
SkimNews Take

Three rival AI coding tools from Anthropic, Google, and OpenAI converging on the same GitHub-issue-to-CI exploit suggests identical assumptions about issue-body safety got independently replicated — a sign the tooling category shipped faster than its threat model was updated.

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: All three major AI coding agents — Claude Code, Gemini CLI, and Codex — were reachable via a routine GitHub issue to their own CI workflows, with Gemini CLI scoring a CVSS 4.0 of 10.0 and every Claude Code release from 0.2.54 onward affected. CISA lists no exploitation and a public reproduction lab has been live since June 18, but OpenAI declined to patch or issue a CVE, leaving the fix to workflow changes — a split response that puts the burden on the developer to know which vendor's "agent layer" they can trust.

Share this story

Ask SkimNews
More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.