CVE-2026-47751: Claude Code Action Dangerous Mcp Toolscve-2026-47751-claude-code-action-dangerous-mcp-tools
The GitHub Action workflow runs the `anthropics/claude-code-action` with powerful, unconstrained MCP tools like `mcp__github__submit_pending_pull_request_review`. If the workflow processes pull requests or issues from untrusted authors, this exposes the system to prompt injection. An attacker could hijack the AI reviewer to abuse these tools or exfiltrate th