FR
live
tag

#claude-code

A GitHub issue with zero repo privileges can run code on Anthropic and Google CI runners — Black Hat 2026 tears apart coding agent trust

On **August 5, 2026**, **Novee Security** demonstrated at **Black Hat USA** that a GitHub issue opened by an account with no write access was enough to execute arbitrary code on the CI runners behind **Claude Code**, **Gemini CLI**, and **OpenAI Codex** repositories. If your CI/CD pipeline executes code from GitHub issues without sandboxing, treat this as a CVE with no patch — yet.

Type at least two characters.

navigate open esc dismiss