Vulnerabilities
A Single GitHub Issue Could Hijack Repos Using Anthropic's Claude Code Action — Now Fixed
Researcher RyotaK of GMO Flatt Security found a flaw in Anthropic's Claude Code GitHub Action that let a single opened issue take over public repos running it. Anthropic fixed it within days (v1.0.94) and paid a bounty; the durable lesson is product-agnostic.