CVE-2026-67610: Claude Code Action Bash Tool Exposure

The GitHub Actions workflow allows the Claude AI action to automatically trigger on untrusted pull requests. An attacker can utilize prompt injection in their pull request code to coerce the AI assistant into executing arbitrary shell commands on the runner. This can lead to sensitive secret compromise and unauthorized repository modification. Restrict the j

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0YAML
greprules fetch cve-2026-67610-claude-code-action-bash-tool-exposure --engine opengrep

Description

The GitHub Actions workflow allows the Claude AI action to automatically trigger on untrusted pull requests. An attacker can utilize prompt injection in their pull request code to coerce the AI assistant into executing arbitrary shell commands on the runner. This can lead to sensitive secret compromise and unauthorized repository modification. Restrict the j