None
EN
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
['The Hacker News', 'Swati Khandelwal', 'Aug']
The Hacker News
Every Claude Code release from 0.2.54 up to 2.1.163 is affected.
Update Gemini CLI to 0.39.1, run-gemini-cli to 0.1.22, and Claude Code to 2.1.163, then audit any workflow an outside user can trigger.
Google addressed both that and the container-launcher flaw in one advisory, which says the fix "affects all Gemini CLI GitHub Actions."
Anthropic rates the Claude Code flaw Moderate at CVSS v4 6.0, while NVD assigned a CVSS v3.1 score of 9.1.
It also found a public GitHub repository describing itself as a reproduction lab for the Claude Code flaw, up since June 18.