2026-10-11 18:01 UTC

Redditor Similar_Job_6080 reports that researchers found unauthenticated GitHub issues could trigger remote code execution through vendor-published Claude Code, Gemini CLI, and Codex Actions configurations, making those defaults unsafe for untrusted issue processing.

state: seedheat: lowuncertainty: highknownscott: lowcoding-agents github-actions agentic-securityAnthropicGoogleOpenAI

What is this?

The case concerns reported attacks on GitHub Actions workflows using Anthropic’s Claude Code, Google’s Gemini CLI, and OpenAI’s Codex, where untrusted issue content could reach privileged CI capabilities. Supplied reporting describes distinct outcomes—API-key exfiltration, host command execution, and changes to instructions for subsequent agent runs—rather than establishing the same RCE in all three. The snippets do not include Novee’s original report or establish the claimed unauthenticated, vendor-default attack path across all three; separate GMO Flatt research says Claude Code Actions blocks non-write users by default, with an explicitly risky option to bypass that restriction.

Why it matters to Scott

Scott already holds the relevant position in Taint Tracking and SiloOS: untrusted text must not authorise privileged actions, and agent containment must be structural; this report supplies another example, not an established challenge to his designs or evidence that his deployments are affected. The radar tracks related attacks, not this exact report, and the supplied grounding does not establish the headline’s unauthenticated vendor-default RCE claim across all three vendors.
ip:concept.taint-trackingip:framework.siloosip:concept.confused-deputy-problemradar:agent-context-privilege-escalationradar:issuetrojanbench-malicious-issue-attacksradar:repository-content-agent-injection
queries asked of Scott's wikis
  • coding agent harness trust boundaries untrusted input
  • GitHub Actions issue triage agent permissions secrets
  • prompt injection tool execution sandbox isolation
  • vendor defaults agent security guarantees
  • agent instruction persistence repository configuration poisoning

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 1610h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

08-05 14:00⭐ origin echo-reconstructedNovee’s original research report says its researchers tested Anthropic Claude Code, Google Gemini CLI, and OpenAI Codex in the vendors’ own
Novee Security (Elad Meged) on blog (echo) · attributed from reddit.post.1wfr3vz
—
09-14 02:33first on r/artificial · published · +948.6hGitHub Actions default configs from Anthropic, Google, and OpenAI's own coding agents were all vulnerable to the same RCE
Similar_Job_6080
—
09-17 20:05first on hacker news · published · +1038.1hPlugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
fishthethis
—
09-14 02:33amplified on r/artificialreddit.post.1wfr3vz
Similar_Job_6080
peak 3 · 5 comments · 19% of case engagement
09-17 20:05amplified on hacker news 👑hn.story.49745809
fishthethis
peak 12 · 3 comments · 64% of case engagement
09-18 13:44amplified on hacker newshn.story.49754342
vitramir
peak 2 · 0 comments · 8% of case engagement
09-19 13:07amplified on hacker newshn.story.49766285
sbulaev
peak 2 · 0 comments · 8% of case engagement
09-14 03:20our radar first saw it · +949.3hdiscovery anchor: reddit.post.1wfr3vz—

Evidence (5) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditGitHub Actions default configs from Anthropic, Google, and OpenAI's own coding agents were all vulnerable to the same RCE
artificial
Similar_Job_608035
🟧 echo.blog ⭐Novee’s original research report says its researchers tested Anthropic Claude Code, Google Gemini CLI, and OpenAI Codex in the vendors’ own Novee Security (Elad Meged)——
🟧 hnPlugin4Shell – Zero Click RCE Vulnerability found in top four coding agentsfishthethis123
🟧 hnPhantomFix: A fake bug to Sentry Seer gets a coding agent to run attacker codevitramir20
🟧 hnAI coding agents' 0-click RCE flaw could hand attackers keys to the kingdomsbulaev20

Interpretation history

Decision trace