CVE-2026-47751: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in anthropics claude-code-action
Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-controlled pull request head branches, read .mcp.json from the working directory via default setting sources, and unconditionally enabled all project MCP servers via enableAllProjectMcpServers, an attacker who opened a pull request containing a malicious .mcp.json file could achieve arbitrary code execution on the GitHub Actions runner and exfiltrate secrets available to the workflow (such as API keys and tokens) when a privileged user or an automatic trigger invoked the Claude action on the pull request. This issue is fixed in version 1.0.74, which restores .claude/ and .mcp.json from the pull request base branch before the CLI runs.
AI Analysis
Technical Summary
Claude Code Action is a GitHub action that runs Claude Code on pull requests and issues. Versions before 1.0.74 improperly checked out attacker-controlled pull request head branches and read .mcp.json files from the working directory without validation, enabling all project MCP servers unconditionally. This allowed attackers to craft malicious .mcp.json files in pull requests to achieve arbitrary code execution on the GitHub Actions runner and exfiltrate secrets such as API keys and tokens when the action was triggered by privileged users or automatic workflows. The vulnerability is addressed in version 1.0.74 by restoring the .claude/ directory and .mcp.json files from the pull request base branch prior to running the CLI, preventing execution of attacker-controlled files.
Potential Impact
An attacker who can open a pull request can execute arbitrary code on the GitHub Actions runner environment and potentially exfiltrate sensitive secrets available to the workflow, including API keys and tokens. This can lead to unauthorized access and compromise of the CI/CD environment and associated resources. The vulnerability requires the action to be invoked by a privileged user or an automatic trigger with sufficient permissions.
Mitigation Recommendations
Upgrade to version 1.0.74 or later, which fixes the vulnerability by restoring .claude/ and .mcp.json files from the pull request base branch before running the CLI. No other mitigation or temporary fix is documented. Patch status is not explicitly confirmed as 'official-fix' in the advisory, but the version 1.0.74 update addresses the issue.
CVE-2026-47751: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in anthropics claude-code-action
Description
Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-controlled pull request head branches, read .mcp.json from the working directory via default setting sources, and unconditionally enabled all project MCP servers via enableAllProjectMcpServers, an attacker who opened a pull request containing a malicious .mcp.json file could achieve arbitrary code execution on the GitHub Actions runner and exfiltrate secrets available to the workflow (such as API keys and tokens) when a privileged user or an automatic trigger invoked the Claude action on the pull request. This issue is fixed in version 1.0.74, which restores .claude/ and .mcp.json from the pull request base branch before the CLI runs.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/anthropics/claude-code-actionRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Claude Code Action is a GitHub action that runs Claude Code on pull requests and issues. Versions before 1.0.74 improperly checked out attacker-controlled pull request head branches and read .mcp.json files from the working directory without validation, enabling all project MCP servers unconditionally. This allowed attackers to craft malicious .mcp.json files in pull requests to achieve arbitrary code execution on the GitHub Actions runner and exfiltrate secrets such as API keys and tokens when the action was triggered by privileged users or automatic workflows. The vulnerability is addressed in version 1.0.74 by restoring the .claude/ directory and .mcp.json files from the pull request base branch prior to running the CLI, preventing execution of attacker-controlled files.
Potential Impact
An attacker who can open a pull request can execute arbitrary code on the GitHub Actions runner environment and potentially exfiltrate sensitive secrets available to the workflow, including API keys and tokens. This can lead to unauthorized access and compromise of the CI/CD environment and associated resources. The vulnerability requires the action to be invoked by a privileged user or an automatic trigger with sufficient permissions.
Mitigation Recommendations
Upgrade to version 1.0.74 or later, which fixes the vulnerability by restoring .claude/ and .mcp.json files from the pull request base branch before running the CLI. No other mitigation or temporary fix is documented. Patch status is not explicitly confirmed as 'official-fix' in the advisory, but the version 1.0.74 update addresses the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.505Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5907ce68715ace4356ca70
Added to database: 07/16/2026, 16:33:18 UTC
Last enriched: 07/23/2026, 22:38:55 UTC
Last updated: 08/27/2026, 22:52:11 UTC
Views: 108
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.