Microsoft discloses Claude Code vulnerability that could steal GitHub credentials
Coinpaper
5h ago
Ai Focus
Microsoft stated that Claude Code's GitHub Actions previously contained a hint injection vulnerability, which allowed attackers to use GitHub content to trick an AI agent into reading and distributing sensitive credentials. Anthropic has since fixed this vulnerability.
Helpful
No.Help

Microsoft researchers have disclosed a previously patched vulnerability in Anthropic's Claude Code GitHub Action. Attackers could have hidden malicious commands in GitHub issues, pull requests, or comments, tricking the AI coding agent into reading sensitive information during the CI/CD process and leaking credentials.

The attack was triggered by GitHub content.

In its blog post, Microsoft stated that this type of risk stems from the fact that AI agents directly process external text content within the development process, and these workflows often have access to sensitive data such as API keys and cloud service credentials. The risk can escalate rapidly if the agent treats untrusted input as executable instructions.

Following Microsoft's testing methodology, researchers set up a GitHub workflow and disguised malicious commands within the content returned by its controlled domain to bypass some of Claude's security protections. Subsequently, Claude Code was tricked into reading a file containing sensitive credentials and rewriting the credential content to evade its own protections and GitHub's key scanning tools.

The credentials can be transmitted through various channels.

Microsoft stated that attackers could theoretically retrieve this information through various methods, including issue comments, workflow logs, web requests, or shell commands. Researchers also intentionally allowed users without write permissions to trigger workflows to verify whether the attack was still possible when environment variable cleanup measures were enabled.

Microsoft stated that they conducted this research because they had previously observed similar hint injection attempts in public repositories related to multiple vendors. A common feature of these attacks is that the attacker-controlled issue or pull request content is read by an AI agent, further influencing its tool invocation behavior.

Anthropic was fixed in May.

Claude Code is an AI coding agent launched by Anthropic last October. The tool also garnered attention in March of this year due to an accidental leak of its source code, which contained over 500,000 lines, prompting extensive analysis of its internal architecture by researchers and developers.

Microsoft stated that it disclosed the issue to Anthropic via HackerOne on April 29. Anthropic subsequently released Claude Code version 2.1.128 on May 5, which fixed the problem.

Microsoft believes this case illustrates that as AI agents are integrated into the software development process, natural language input is increasingly resembling "executable code." In this scenario, external content such as GitHub issues and comments need to be treated as untrusted input by default; otherwise, a single carefully crafted piece of information could become an entry point for obtaining credentials for the production environment.

Tip
$0
Like
0
Save
0
Views 974
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Zcash discloses Orchard vulnerability that could allow for the forgery of unlimited ZEC.
Zcash has disclosed a serious vulnerability in the Orchard shielding pool, which could theoretically allow for the creation of an unlimited number of ZECs. The team says there is currently no evidence that the vulnerability has been exploited.
AMBCrypto
·2026-06-06 00:29:22
909
Trezor discloses vulnerability in Safe 7 chip: claims user assets unaffected
Trezor claims that the chip used in Safe 7 has a lab-level vulnerability, but user assets are not affected.
CoinDesk
·2026-06-03 18:15:35
283
Anthropic stated that Claude has generated the majority of production code.
Anthropic stated that Claude currently generates over 80% of the company's production code and can continuously execute software engineering tasks for up to 12 hours.
CoinPedia
·2026-06-05 10:58:11
832
Microsoft released seven AI models, claiming that some outperformed Claude and Google.
Microsoft released seven MAI series AI models, claiming that some test results surpassed those of Anthropic and Google products, indicating that it is accelerating the development of its own cutting-edge models.
Coinpaper
·2026-06-03 06:45:42
218
Strategy discloses first Bitcoin sale in two years
Strategy disclosed its first Bitcoin sale since 2022, drawing market attention to changes in its treasury strategy.
Cryptonews
·2026-06-03 15:47:06
1003