GeistHaus
log in · sign up

Trusting Claude With a Knife: Unauthorized Prompt Injection to RCE in Anthropic’s Claude Code Action

johnstawinski.com

An external attacker could submit a pull request to any repository using Claude Code Action, wait for a reviewer to trigger the action, and then replace the PR title with a prompt injection payload…

0 pages link to this URL

No pages have linked to this URL yet.