Flaws in Claude Code and Gemini CLI Expose CI Secrets via GitHub Issue
Security researchers discovered vulnerabilities in Claude Code and Gemini CLI that let a specially crafted GitHub issue access secrets stored in CI workflows. The attack exploits how these developer tools handle untrusted input. This matters because compromised CI secrets could lead to supply-chain attacks or unauthorized access to cloud infrastructure.