2026-08-10NOTABLEA validator that strips quoted text before inspecting it, and an agent instruction file rewritten between two passes of one shared checkout
claude-code-action bot-actor bypass
trend · trend:claude-code-action-github-issue-supply-chain
claude-code-action [bot]-actor bypass plus prompt injection enabling repo hijack / action poisoning; fixed in v1.0.94.
Coverage
1
first 2026-06-05 → last 2026-08-10
Latest activity
2026-08-10
A validator that strips quoted text before inspecting it, and an agent instruction file rewritten between two…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology · regions: europe
Sources cited
4
4 hosts
Action items (1)
Do-now tasks recorded on the entries about claude-code-action bot-actor bypass, newest first. Check the date before acting on an older one.
- Audit any CI workflow where two or more agent passes share a single checkout; the Codex fix was to split the passes into separate jobs each with its own checkout, and that change has to be made in your own pipelines because no vendor patch reaches them.2026-08-10CVE-2026-54316 +1
Defender insights
What each entry about claude-code-action bot-actor bypass tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (4 across 4 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise: Compromise Software Supply Chain
- ExecutionCommand and Scripting Interpreter: Unix Shell
- Credential AccessUnsecured Credentials
- ExfiltrationExfiltration Over Web Service
Initial Access TA0001
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-08-10/coding-agent-ci-harness-trust-boundary-shared-checkout · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-08-10/coding-agent-ci-harness-trust-boundary-shared-checkout · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-08-10/coding-agent-ci-harness-trust-boundary-shared-checkout · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-08-10/coding-agent-ci-harness-trust-boundary-shared-checkout · ATT&CK page ↗
Entries about claude-code-action bot-actor bypass (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Anthropic Claude Code×1
- Anthropic Claude Code Action, CI command-validation bypass (quote-stripping before inspection; read-only allowlist exempt from path checks); fixed claude-code 2.1.163, published 2026-06-13×1
- Coding-agent CI harness trust-boundary failures×1
- Google Gemini CLI×1
- Google Gemini CLI GitHub Actions harness, trust-boundary bypass; fixed gemini-cli 0.39.1 / run-gemini-cli 0.1.22, published 2026-04-24×1
- OpenAI Codex×1
Where this entity is cited
Source distribution
- api.osv.dev1 (25%)
- github.com1 (25%)
- novee.security1 (25%)
- services.nvd.nist.gov1 (25%)
All cited sources (4)
- api.osv.devOSVhttps://api.osv.dev/v1/vulns/GHSA-wpqr-6v78-jr5g
- github.comAnthropic (GitHub Security Advisory)https://github.com/anthropics/claude-code/security/advisories/GHSA-fg94-h982-f3mm
- novee.securityNovee Securityhttps://novee.security/blog/critical-flaws-in-anthropic-google-and-openais-coding-agents/
- services.nvd.nist.govNVD/MITRE CVE record, 2026-08-28https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-12537