ended6월 3일· 1 sources

From Comments to Credentials: How Attackers Hijack AI Coding Agents in CI/CD

GitHub 댓글이 무기가 되다, AI 에이전트 시크릿 탈취 취약점 발견

Why it matters

Major AI coding agents deployed in GitHub Actions—including Claude Code, Gemini CLI, and GitHub Copilot—are vulnerable to a fundamental architectural flaw: attackers with minimal privileges can inject malicious prompts through public comments to exfiltrate sensitive secrets. Rated CVSS 9.4 Critical, this vulnerability cannot be patched inside the agents themselves since their core function is to read and act on untrusted input.

1
Sources
+0
24h
Growth
6d
Active
Prompt injectionClaude CodeGitHub ActionsAI agentsSecret exfiltration

Sources

Related Issues