SECURITY·중요도 9·2026. 08. 07.·The Hacker News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
── KO ──────────────────
Claude Code와 Gemini CLI의 결함이 GitHub CI 비밀을 노출시켰습니다.
Novee Security는 GitHub에서 권한 없는 계정으로 생성된 이슈가 Anthropic과 Google의 CI 러너에서 코드를 실행하는 데 충분했다고 보고했습니다. 이들은 Black Hat USA에서 발표하며 각 공급자의 기본 설정을 사용하여 공격을 수행했습니다. OpenAI의 경우, 다음 에이전트 실행을 탈취하는 데도 성공했습니다.
── EN ──────────────────
Flaws in Claude Code and Gemini CLI exposed CI secrets on GitHub.
Novee Security reported that a GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners of Anthropic and Google's repositories. They demonstrated this attack at Black Hat USA, highlighting the default configurations of each vendor. In OpenAI's case, it was also possible to hijack the next agent run.