Community Articles

via Decrypt · By Decrypt Editorial

Claude Code Vulnerability Could Let Attackers Steal Credentials From GitHub, Says Microsoft

DE
Decrypt Editorial
(06:08 PM UTC)
1 min read
EW
Approved byEmily Watson

In brief

  • Microsoft researchers found that Anthropic's Claude Code GitHub Action could be manipulated through prompt injection attacks.
  • The attack relied on malicious instructions hidden in GitHub issues, pull requests, or comments that the AI agent was asked to review.
  • Anthropic patched the vulnerability in May after Microsoft disclosed the issue through HackerOne.

Microsoft researchers disclosed…

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google

Source

Decrypt Editorial · Decrypt

Read original →

Comments
Comments
Other Community Articles