GitHub Actions default configs from Anthropic, Google, and OpenAI’s own coding agents were all vulnerable to the same RCE
Security researchers found that the default GitHub Actions configuration each of the three major labs publishes for their own coding agents (Claude Code, Gemini CLI, and Codex) could all be tripped by a single unauthenticated GitHub issue, ending in re…