Anthropic recently patched a security vulnerability in Claude Code, a command-line AI coding assistant used by developers to automate software tasks. Researchers discovered that the tool's GitHub Action could be manipulated through indirect prompt injection, where malicious instructions are hidden in pull requests or issues. This flaw allowed attackers to bypass security boundaries and exfiltrate sensitive data, such as API keys and environment variables, from CI/CD workflows.
Source