Novee Security disclosed at Black Hat USA 2026 that AI coding agents tied to GitHub workflows can be manipulated through untrusted issue, pull request, and workflow-generated content to execute malicious actions inside repositories they are meant to maintain. Testing of Anthropic Claude Code, Google Gemini CLI, and OpenAI Codex against the vendors’ own public repositories and default setups showed paths to remote code execution, credential theft, repository tampering, and software supply-chain compromise without requiring privileged access.
Researchers said the weakness lies primarily in the surrounding agent harnesses—tool permissions, execution controls, and sandboxing—rather than the underlying models. Reported exploitation paths included command-validation bypasses, unenforced shell restrictions, secret exposure through /proc, and persistent instruction poisoning across multi-pass workflows. Anthropic remediated CVE-2026-54316 in Claude Code versions 0.2.54 through 2.1.162; Google patched Gemini CLI versions before 0.39.1, preview versions before 0.40.0-preview.3, and run-gemini-cli GitHub Action versions before 0.1.22; OpenAI mitigated Codex workflow risk by isolating agent runs and using read-only environments. The researchers said they found similar insecure patterns in more than 100 public repositories and reported no evidence of malicious exploitation in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
At Black Hat USA 2026, Novee Security disclosed its research on AI coding agents integrated with GitHub workflows, covering Anthropic Claude Code, Google Gemini CLI, and OpenAI Codex. The presentation reported controlled proof-of-concept research and said no malicious exploitation in the wild had been identified.
OpenAI corrected its Codex repository workflow within three days by separating agent runs into isolated jobs and checkouts and moving them into read-only environments. The change mitigated persistence of attacker-written AGENTS.md instructions across multi-pass runs.
The critical Gemini CLI compromise path was assigned CVE-2026-12537. Novee Security described it as an OS command injection in the container launcher reachable through a crafted .gemini/.env file, enabling host-level code execution on headless CI runners before sandboxing begins.
Google rated the Gemini CLI compromise path as critical with a CVSS score of 10.0 and patched affected versions before 0.39.1, preview versions before 0.40.0-preview.3, and run-gemini-cli GitHub Action versions before 0.1.22. The issue involved unenforced shell restrictions and exposure of secrets from the parent process via /proc.
Anthropic fixed the Claude Code flaw affecting versions 0.2.54 through 2.1.162 in version 2.1.163. The remediation addressed the final issue tracked as CVE-2026-54316.
A later Claude Code exfiltration method abusing pre-approved Hugging Face access was tracked as CVE-2026-54316. The issue enabled stolen information to be encoded into requests to an attacker-controlled Hugging Face repository and reconstructed via download counts.
After Novee Security demonstrated an initial Claude Code exploit path involving a malicious git push command that bypassed validation and executed code on a GitHub Actions runner, Anthropic blocked that route. Researchers then continued to find additional Claude Code bypass methods.
Novee Security researcher Elad Meged identified a repeatable vulnerability pattern in AI coding agents from Anthropic, Google, and OpenAI by testing the vendors’ default configurations on their own public repositories. The research showed paths from untrusted GitHub issue or pull request content to remote code execution, credential theft, and supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.