Overview
Security researchers at Novee Security revealed critical flaws in Claude Code and Google’s Gemini CLI that allowed unprivileged GitHub issues to reach CI/CD workflow secrets. Presented at Black Hat USA 2026, the findings highlight how weaknesses in agent harnesses—the code bridging models and real-world execution—can bypass safeguards and expose sensitive infrastructure.
Key Vulnerabilities
- Gemini CLI flaw
- CVE‑2026‑12537 (CVSS 10.0).
- OS command injection via crafted
.gemini/.envfiles. - Allowed attackers to run code on CI hosts before sandboxing.
- Fixed in Gemini CLI 0.39.1 and run‑gemini‑cli 0.1.22.
- Claude Code flaw
- CVE‑2026‑54316.
- Exploited Hugging Face’s public download counter to leak API keys one character at a time.
- Affected versions 0.2.54 through 2.1.163.
- Fixed in Claude Code 2.1.163.
- OpenAI Codex workflow issue
- No CVE assigned.
- Codex ran two passes in one job, allowing the first to overwrite
AGENTS.mdinstructions for the second. - OpenAI mitigated by separating passes into different jobs, enforcing read‑only sandboxes, and updating documentation.
Root Cause: Harness Weaknesses
Across all three agents, the recurring failure was in the harness layer:
- Values marked “safe” were later executed with elevated authority.
- Claude Code’s validator stripped single‑quoted text, letting payloads slip through.
- Gemini CLI enforced tool allowlists only at registration, not runtime.
- Codex workflows treated repository instruction files as trusted, leaving them writable.
As Novee’s Elad Meged explained: “The harness is the code between the model and the real world.”
Security Impact
- Attackers could hijack CI runners or exfiltrate secrets without persuading the model to misbehave.
- Exploitation required only untrusted content in agent contexts or crafted GitHub issues.
- While no exploitation has been confirmed in the wild, a public GitHub repo reproducing the Claude Code flaw has been online since June 18.
Defensive Guidance
- Update affected versions:
- Gemini CLI ≥ 0.39.1, run‑gemini‑cli ≥ 0.1.22.
- Claude Code ≥ 2.1.163.
- Audit workflows: Review any CI/CD jobs triggered by outside users.
- Treat repository files as untrusted: Instruction files like
AGENTS.mdshould be considered part of the attack surface. - Enforce runtime checks: Ensure allowlists apply during execution, not just registration.
- Monitor outbound exfiltration: Detect unusual API calls or download counter anomalies.
Expert in the Cloud Insight
These flaws underscore that AI agents are only as secure as their harnesses. Even when models behave correctly, weak execution layers can expose secrets and infrastructure. For defenders, the lesson is clear: audit workflows, enforce runtime validation, and treat all external inputs—including GitHub issues—as untrusted surfaces.
Leave a Reply