we_are_coded.by CODE · The world, decoded
БГ
Coding agents

One public issue could reach a workflow's secrets - in Claude Code and Gemini CLI alike

AnthropicSecurity

At Black Hat, researchers walked through the chain: a stranger with no permissions opens an issue in a public repo, and the coding agent walks tokens and keys out the door. The patches shipped back in April and June - what's new is that the chain was told in public.

In short
  • Two separate holes with official numbers: CVE-2026-12537 in Gemini CLI (scored 10.0 by Google) and CVE-2026-54316 in Claude Code (6.0 per Anthropic, 9.1 per the US national registry).
  • The entry point in both cases is a public GitHub issue from a person with no permissions, which triggers a workflow. The exit is tokens, keys and files from that same environment.
  • The patches are Claude Code 2.1.163 and Gemini CLI 0.39.1. For Gemini, updating alone is not enough - it also takes an explicit trust setting for the folder.
Checked on7 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Here is the trap. The agent was not broken from the inside. What broke was the boundary between what it reads and what it can reach. A person with no permissions opens an issue in a public repo, and a few minutes later the workflow's token has walked out the door.

The facts: on 5 August at Black Hat in Las Vegas, Elad Meged of Novee Security demonstrated the chain, and on 6 August the firm published it on its blog. These are two separate vulnerabilities, each with its own official record. For Gemini CLI: GHSA-wpqr-6v78-jr5g from 24 April, scored 10.0 - the ceiling of the scale, and CVE-2026-12537, entered into the US national registry on 24 June. For Claude Code: GHSA-fg94-h982-f3mm from 13 June, that is CVE-2026-54316. Affected are @anthropic-ai/claude-code from 0.2.54 to 2.1.163 and @google/gemini-cli before 0.39.1.

The two chains differ, but they meet at the same point. Gemini CLI, running in automatic mode, trusted the working folder without checking it. The attacker drops a file into it and the command runs on the machine itself, before the sandbox has even started. Separately, the allowlist of permitted tools was matched by the start of the text, so an entry like 'run only echo' effectively unlocked the whole shell.

With Claude Code the trick is quieter, and that makes it prettier as craft. The address huggingface.co sat on the pre-approved list as a bare domain. So every URL under it passes without question, including a repository owned by the attacker. And since HuggingFace counts requests as downloads, the public download counter becomes a channel through which data leaks out character by character. No window asks, no log screams.

One and the same hole: Anthropic scores it 6.0, the US national registry - 9.1.

That gap is not small and should not be smoothed over. Anthropic measures on the new scale and sees moderate; the state registry measures on the old one and sees critical. Both scores are official. Anyone who quotes you only one of them is selling you a mood.

And since the story spread yesterday under headlines that read like a fresh breach - it is not one. The Gemini patch is nearly four months old, the Claude Code one is two. Anyone updating automatically was protected before ever hearing the story. What is new is the telling, not the hole.

The bottom line: check the version, don't assume. For Gemini, updating by itself does not close the question - the fix changes how trust in the folder is treated and requires an explicit setting. And the most important thing that remains after the patches are in: look at which of your workflows a stranger can trigger, and what secrets sit in that same environment. The hole was at the seam between checking and executing, not in the model.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Anthropic - GHSA-fg94-h982-f3mm (Claude Code)→Google - GHSA-wpqr-6v78-jr5g (run-gemini-cli)→NVD - CVE-2026-12537→Novee Security - the research
Original: https://wearecoded.com/en/articles/claude-code-gemini-cli-issue-do-tayni.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news