# Flaws in Claude Code and Gemini CLI Expose CI Secrets via GitHub Issue

Security researchers discovered vulnerabilities in Claude Code and Gemini CLI that let a specially crafted GitHub issue access secrets stored in CI workflows. The attack exploits how these developer tools handle untrusted input. This matters because compromised CI secrets could lead to supply-chain attacks or unauthorized access to cloud infrastructure.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html) — Fri, 07 Aug 2026 13:48:35 +0530