PT-2026-48540 · Github Actions+2 · Anthropics/Claude-Code-Action+1

CVE-2026-47751

·

Published

2026-06-10

·

Updated

2026-07-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Claude Code Action versions prior to 1.0.74
Description An issue exists where the action checks out attacker-controlled pull request head branches and reads the .mcp.json file from the working directory. Because all project MCP (Model Context Protocol) servers are unconditionally enabled via enableAllProjectMcpServers, an attacker can include a malicious .mcp.json file in a pull request to achieve arbitrary code execution on the GitHub Actions runner. This can lead to the exfiltration of workflow secrets, such as API keys and tokens, when a privileged user or an automatic trigger invokes the action on the pull request.
Recommendations Update to version 1.0.74 or later.

Exploit

Fix

OS Command Injection

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47751
GHSA-8Q5R-MMJF-575Q

Affected Products

Anthropics/Claude-Code-Action
Claude-Code-Action