A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic’s own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.
RyotaK of GMO –
Read More – The Hacker News



![[Webinar] Why Your AppSec Tools Miss the “Lethal Path” (and How to Fix It) AttackFeed by Joe Wagner | [Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It) - The Hacker News](https://attackfeed.com/wp-content/uploads/2026/05/wiz-P5vlHe.jpg)