How a GitHub Triage Role Hijacked an Already-Authorized Claude Code Action Run
This story is from 2026-08-31. It is preserved in the archive; the latest stories are on the live feed.
A GitHub collaborator with only the triage role could shift Claude Code Action's authorized trigger boundary and inject post-authorization input into a repository-writing run. HackerOne #3918594 · Claude Code Action v1.0.185, commit 9db594c7a0e82298c121c18b7f08aa1579ce7341 · CVSS 4.0 score 7.5, Hig…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-31 09:14 · DEV Community — AI
How a GitHub Triage Role Hijacked an Already-Authorized Claude Code Action Run