AI/ML

AI coding tools vulnerable to malicious GitHub issues

The GitHub logo is displayed on a smartphone screen

AI coding tools from Anthropic, Google, and OpenAI were found to be vulnerable to malicious instructions embedded in public GitHub issues. Researchers at Novee Security demonstrated how these vulnerabilities could lead to remote code execution, credential theft, and repository modification, according to HackRead.

Novee Security researchers discovered flaws in Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex. For Claude Code, an attacker could exploit hidden instructions within a GitHub issue to execute code on the GitHub Actions runner, potentially exposing API tokens and allowing repository modification. A subsequent flaw allowed data theft by encoding information into requests to a controlled Hugging Face repository. Google's Gemini CLI received a critical CVSS score of 10.0 due to a vulnerability that allowed access to sensitive credentials by reading the parent process's environment. OpenAI's Codex issue-deduplication workflow was susceptible to persistent instructions between agent runs, allowing an attacker to manipulate a second agent by creating a malicious file.

While vendors have issued fixes, Novee Security noted that similar configurations exist in over 100 public repositories, urging companies to review their workflows and limit token permissions.

Source: HackRead

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds