By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Claude Code and Gemini CLI Flaws Exposed CI Secrets

Security researchers at Novee Security demonstrated critical vulnerabilities in the default configurations of coding agents from Anthropic and Google, enabling unauthorized code execution on their respective CI (Continuous Integration) runners. The attack, presented at Black Hat USA on August 5, exploited flaws in Anthropic's Claude Code and Google's Gemini CLI. Specifically, a GitHub issue created by an account lacking repository privileges was sufficient to trigger code execution on the CI runners associated with Anthropic's and Google's own coding-agent repositories. On OpenAI's platform, a similar issue was potent enough to hijack the subsequent agent run. Novee Security conducted these tests against each vendor's agent in its out-of-the-box configuration, highlighting the risks inherent in default settings. The implications of these findings are significant, as CI runners often have access to sensitive secrets, including API keys, credentials, and proprietary code. The successful exploitation of these vulnerabilities means that an attacker could potentially gain access to these secrets, leading to further compromise of systems and data. The default shipping configuration is particularly concerning, as it implies that many users might be exposed to these risks without implementing additional security measures. The research underscores the ongoing challenges in securing AI-powered development tools and the critical need for rigorous security auditing and hardening of these systems before deployment. The Black Hat USA conference is a prominent cybersecurity event where researchers present cutting-edge security research and findings. The presentation by Novee Security at this venue suggests a high level of confidence in their discovered vulnerabilities and their potential impact on the broader cybersecurity landscape. The specific details of the exploit, such as the exact nature of the flaws in Claude Code and Gemini CLI, and the precise mechanism by which the GitHub issue triggered code execution, are crucial for understanding the scope of the threat. However, the core finding remains that these widely used AI coding assistants, in their default states, presented significant security risks that could lead to the exposure of sensitive development secrets. This incident serves as a stark reminder for organizations to thoroughly vet and secure any AI tools integrated into their development pipelines, paying close attention to default configurations and implementing robust security protocols to mitigate potential exploitation.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.