
Security Flaws in Anthropic's Claude Code and Google's Gemini CLI Enable Unprivileged Code Execution
AI SecurityVulnerabilitiesCode ExecutionSupply Chain Attacks
A security flaw in Anthropic's Claude Code and Google's Gemini CLI allowed a GitHub issue opened by an unprivileged account to execute code on CI runners used by the vendors' coding-agent repositories. On OpenAI's platform, the same attack could hijack the next agent run. Novee Security demonstrated the exploit against each vendor's default agent configuration and presented findings at Black Hat USA on August 5, 2026. The attack required no repository privileges and targeted the default deployment setups of the affected AI coding agents. No CVE IDs or specific technical details of the vulnerability were disclosed in the report.