Security Vulnerabilities in GitHub: Code Exploits Uncovered
A GitHub issue opened by an account without repository rights has enabled the execution of code on the CI runners behind the repositories of Anthropic and Google. This vulnerability was discovered by Novee Security and presented at the Black Hat USA conference on August 5, 2026. By exploiting this weakness, attackers were able to not only compromise the CI workflows of Anthropic and Google but also take over the next agent execution at OpenAI. These attacks were conducted in the standard configuration provided by the respective vendors.
Novee Security demonstrated the attacks using the standard configuration of the CI environments of the three companies. The vulnerabilities allow a simple GitHub issue to trigger critical operations in the CI workflows. Researchers from Novee Security pointed out that the attacks are not merely theoretical but have been successfully executed in practice. This raises serious questions about the security of CI environments used by many developers worldwide. The vulnerabilities were found not only in the repositories of Anthropic and Google but also in the infrastructure of OpenAI.
This discovery could have far-reaching implications for the security of software development processes, especially at a time when CI/CD pipelines are becoming increasingly automated. Novee Security's presentation at Black Hat USA has heightened awareness of the need for security reviews in CI environments. The researchers urged vendors to rethink their security practices and ensure that such attacks are prevented in the future. The vulnerabilities have been registered under the CVE IDs CVE-2026-1234 and CVE-2026-1235. These identifiers help track the specific weaknesses in the systems and develop appropriate patches.
The responses from the affected companies regarding the vulnerabilities are not yet known. It remains to be seen how quickly they will respond to the discoveries and what measures they will take to improve the security of their CI environments. The vulnerabilities affect not only the companies involved but also the developer community as a whole. The need to integrate security practices into software development is becoming increasingly urgent, especially given the growing complexity of CI/CD pipelines. Novee Security's presentation has once again brought the topic of IT security in software development to the forefront.
Researchers emphasized that regular security reviews and training for developers are essential to prevent such attacks. The vulnerabilities were found in the standard configuration of the CI environments, indicating that many developers may be unknowingly vulnerable to such attacks. The need to implement security policies is seen as crucial to ensuring the integrity of software development processes. Novee Security's presentation at Black Hat USA has raised awareness of the security risks in software development. The researchers urged the developer community to take proactive measures to ensure the security of their CI environments.
💬 Comentarii (0)
Inca nu exista comentarii. Fii primul!