Microsoft Discovers Prompt Injection Vulnerability in Claude Code That Could Expose GitHub Credentials

According to Microsoft researchers, on Friday, a vulnerability was discovered in Anthropic's Claude Code GitHub Action that could allow attackers to steal credentials stored in software development pipelines through prompt injection attacks. Attackers could hide malicious instructions in GitHub issues, pull requests, or comments to manipulate the AI agent into exposing sensitive information such as API keys and cloud credentials. Anthropic patched the vulnerability on May 5 after Microsoft disclosed the issue through HackerOne on April 29.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments