CVE Tools
Back to feed
Research Gemini CLI ai-ml Claude Code Google web-app

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Researchers discovered severe vulnerabilities in AI-powered coding agents from Google, Anthropic, and OpenAI, allowing attackers to extract sensitive secrets from continuous integration (CI) workflows using a simple GitHub issue. The flaws were demonstrated during an attack that exploited default configurations of each vendor's tools, leading to the disclosure of two CVEs. CVE-2026-12537, affecting Gemini CLI, enables remote code execution on CI runners with a CVSS score of 10.0 and is fixed in version 0.39.1. CVE-2026-54316 in Claude Code leaks API keys through a public download counter, rated as Moderate by Anthropic but high at 9.1 by NVD, and resolved in 2.1.163. Neither Codex nor its associated findings received a specific patch or CVE, though OpenAI updated its documentation and workflows. Users are advised to apply updates and review their CI processes for potential exposure.