PT-2026-48540 · Github Actions+2 · Anthropics/Claude-Code-Action+1
CVE-2026-47751
·
Published
2026-06-10
·
Updated
2026-07-16
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Claude Code Action versions prior to 1.0.74
Description
An issue exists where the action checks out attacker-controlled pull request head branches and reads the
.mcp.json file from the working directory. Because all project MCP (Model Context Protocol) servers are unconditionally enabled via enableAllProjectMcpServers, an attacker can include a malicious .mcp.json file in a pull request to achieve arbitrary code execution on the GitHub Actions runner. This can lead to the exfiltration of workflow secrets, such as API keys and tokens, when a privileged user or an automatic trigger invokes the action on the pull request.Recommendations
Update to version 1.0.74 or later.
Exploit
Fix
OS Command Injection
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anthropics/Claude-Code-Action
Claude-Code-Action