Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Incident: Nissan discloses cyber incident in Australia and NZ | iTnews

    April 9, 2026

    Incident: University of Wollongong discloses data breach | iTnews

    April 9, 2026

    Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks | Blog

    April 9, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»Alerts»Anthropic Claude Code Action Runner Arbitrary Code Execution via Malicious MCP Server Configuration – Research Advisory
    Alerts

    Anthropic Claude Code Action Runner Arbitrary Code Execution via Malicious MCP Server Configuration – Research Advisory

    adminBy adminApril 9, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Synopsis

    The claude-code-action GitHub Action checks out the PR head branch when operating in a pull request context, making the working directory attacker-controlled. Combined with the action unconditionally setting ‘enableAllProjectMcpServers’ to ‘true’ in Claude Code’s user settings and loading settings from project and local source by default ‘(settingsSource: [“user”, “project”, “local”])’, an attacker can supply a malicious ‘.mcp.json’ file in his PR branch.

    When a privileged user triggers the GitHub Action (via an ‘issue_comment’ event for example), the MCP server defined in the attacker-controlled configuration is automatically started without approval, resulting in arbitrary command execution in the runner with access to all workflow secrets.

    Disclosure Timeline

    February 12, 2026: Tenable reports the finding to Anthropic.

    February 13, 2026: HackerOne Bot triages the vulnerability as informative stating it’s a configuration issue rather than a vulnerability.

    February 13, 2026: Tenable confirms it’s not a misconfiguration but a vulnerability.

    February 13, 2026: Anthropic reopens the report and triages it with low severity.

    February 14, 2026: Tenable asks for details about the severity assessment (high vs low)

    February 22, 2026: Anthropic reevaluates the severity to medium.

    March 9, 2026: Tenable requests for an update about fix release expectations.

    March 13, 2026: Anthropic confirms fix is in progress.

    March 16, 2026: Tenable requests for a new severity review.

    March 24, 2026; Anthropic confirms the medium severity and confirms a fix has been released.

    March 25, 2026: Tenable confirms that the fix seems to be working.

    All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

    Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers.
    Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

    For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

    If you have questions or corrections about this advisory, please email
    [email protected]



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSimplify Security Management with CIS SecureSuite Platform
    Next Article Incident: St Vincent’s Health network hit by cyber attack, with data stolen | ABC News Australia
    admin
    • Website

    Related Posts

    Alerts

    Incident: Nissan discloses cyber incident in Australia and NZ | iTnews

    April 9, 2026
    Alerts

    Incident: University of Wollongong discloses data breach | iTnews

    April 9, 2026
    Alerts

    Incident: St Vincent’s Health network hit by cyber attack, with data stolen | ABC News Australia

    April 9, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202617 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202617 Views
    Our Picks

    Incident: Nissan discloses cyber incident in Australia and NZ | iTnews

    April 9, 2026

    Incident: University of Wollongong discloses data breach | iTnews

    April 9, 2026

    Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks | Blog

    April 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.