← Back

Wire · technology

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Published

7 August 2026

Topic

technology

◆ Sectors

AI Frontier ModelsGenerative AIDeveloper Tools

◆ Geography

United States

◆ Source

Read at thehackernews.com →

◆ Verified

Fusion42 · 7 August 2026 · Fusion42 review

Critical vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI allowed unprivileged GitHub issues to execute code on CI hosts and leak secrets. Patches have been released and users must update and audit workflows exposed to outside users.

This Wire brief sits within Fusion42's coverage of AI Frontier Models, Generative AI and Developer Tools.

◆ ◆ The Wire takeaway

You must urgently update Gemini CLI and Claude Code to patched versions and review any GitHub workflows that allow external trigger. This flaw turned routine issue submissions into a critical break-in point that exposes your secrets and code execution paths.

◆ Coverage

1 source · 7 Aug 2026

◆ Related on Wire

◆ Topics

AI Frontier ModelsGenerative AIDeveloper Toolsci-securityvulnerabilitygithubcommand-injectionsecrets-leak