agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

A single malicious GitHub issue could make CI-wired Claude Code exfiltrate secrets via Hugging Face download counts (CVE-2026-54316)

2026-claude-code-ci-hf-exfiltration · 2026-08-05

At Black Hat USA 2026, researchers (Novee Security) showed that an unprivileged attacker opening one GitHub issue could reach credentials held by AI coding agents wired into a repository's CI. In Claude Code (CVE-2026-54316), the attack abused its pre-approved Hugging Face access: the agent was induced to encode stolen data into requests to an attacker-controlled Hugging Face repository, which the attacker reconstructed by monitoring download counts.

System

Framework
Claude Code (in CI / GitHub Actions)
Tools
github-actions, huggingface, ci
Vendor
Anthropic
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → data-exfiltration/via-tool
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

An unprivileged GitHub account — no write access, no relationship with the maintainers — opened a single issue in a repository whose CI wires in an AI coding agent. The injected content directed Claude Code to make requests to an attacker-controlled Hugging Face repository (a destination it had pre-approved access to), encoding stolen CI information into those requests; the attacker reconstructed the data by watching download counts on repositories they controlled.

Root cause

A CI-embedded agent acted on instructions from untrusted issue content and had standing, pre-approved access to an external service that could be turned into a covert exfiltration channel. Pre-approved outbound access plus untrusted input let injected instructions move CI secrets out via a side channel.

Contributing factors

  • The agent had pre-approved access to an external service (Hugging Face) usable as an exfiltration channel.
  • Untrusted GitHub issue content was treated as actionable instructions in a CI context holding secrets.
  • A download-count side channel let data leave without an obviously sensitive outbound request.

Detection

Discovered and presented at Black Hat USA 2026 by Novee Security, with working attack chains also demonstrated against Google's Gemini CLI and OpenAI's Codex; tracked for Claude Code as CVE-2026-54316.

Recovery

Anthropic fixed the issue in Claude Code v2.1.163 (affected versions 0.2.54 through 2.1.162); Google rated its Gemini CLI variant CVSS 10.0 and changed its trust model for non-interactive execution.

Prevention

Do not grant CI agents standing pre-approved access to external services that can serve as exfiltration channels; treat issue/PR content as untrusted; remove or scope write tokens and secrets in agent-run CI jobs; isolate process environments; require approval for outbound requests carrying data.

Blast radius

Data
CI credentials/secrets from repositories using AI coding agents could be exfiltrated; the broader research showed chains leading to credential theft and potential software-supply-chain compromise. credentials
User harm
A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
Scope
repositories running Claude Code in CI (affected versions 0.2.54–2.1.162)
Reversibility
reversible

References

CWE
CWE-200
OWASP LLM
LLM01 LLM02
MITRE ATLAS
AML.T0024 AML.T0051
Tags
prompt-injection data-exfiltration ci github huggingface side-channel black-hat cve

Sources

Cite this incident

@misc{2026-claude-code-ci-hf-exfiltration,
  title = {A single malicious GitHub issue could make CI-wired Claude Code exfiltrate secrets via Hugging Face download counts (CVE-2026-54316)},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-claude-code-ci-hf-exfiltration/}
}