Security Vulnerability at GitHub: CI Workflow Compromised
A security vulnerability at GitHub allows for the compromise of CI workflow secrets. Novee Security presented the findings at Black Hat USA.
A recently discovered security vulnerability at GitHub has allowed attackers to access confidential information in the Continuous Integration (CI) workflows of Anthropic, Google, and OpenAI. This vulnerability was identified by Novee Security and presented at the Black Hat USA conference on August 5, 2026. The attacks were carried out against the default configurations of the respective coding agent repositories.
The security flaw is based on the possibility that a GitHub issue can be created by a user without repository rights. This seemingly harmless action was sufficient to execute code on the CI runners of the affected companies. This poses a significant risk, as it allows attackers to take control of the CI environment and steal sensitive data.
Novee Security demonstrated the attacks by using the default configurations of the coding agent repositories of Anthropic, Google, and OpenAI. At Anthropic and Google, it was possible to execute code on the CI runners by creating a GitHub issue. In contrast, at OpenAI, it was enough to take over and manipulate the next agent run.
Novee Security's presentation at Black Hat USA has drawn the attention of the security community to the potential dangers associated with the use of CI workflows. The possibility that an attacker can access critical systems without special permissions raises serious questions about the security of software development processes.
Reactions from the Affected Companies
Following the presentation of the findings, Novee Security informed the affected companies about the discovered vulnerabilities. Anthropic, Google, and OpenAI have already begun investigating the incidents and are working on solutions to address the security vulnerabilities. The companies have emphasized that they take the security of their systems and the integrity of their users' data seriously.
The security flaw has also sparked discussions about the need for stricter security protocols and policies in software development. Experts are calling for companies to regularly check their CI environments for vulnerabilities and ensure that only authorized users have access to critical functions.
Impact on the Developer Community
The discovery of this security vulnerability could have far-reaching implications for the developer community. Many companies use CI workflows to automate and optimize their software development processes. The possibility that a simple GitHub issue could lead to a security incident may cause developers to rethink their workflows and implement additional security measures.
The security incidents underscore the importance of training and awareness regarding security issues in software development. Developers need to be aware of the risks associated with using CI workflows and take appropriate measures to protect their projects.
The security vulnerability has already been classified in the professional community as one of the most significant discoveries of 2026. Novee Security's presentation at Black Hat USA has raised awareness of the need for security measures in software development and could lead to increased collaboration between companies and security researchers.
comment Kommentare (0)
Noch keine Kommentare. Schreiben Sie den ersten!
Kommentar hinterlassen