Claude Code Action arbitrary code execution via malicious .mcp.json
A vulnerability in Claude Code Action prior to version 1.0.74 allowed attackers to achieve arbitrary code execution on GitHub Actions runners by including a malicious .mcp.json file in pull requests, potentially exfiltrating workflow secrets like API keys and tokens.
Disclosed 16 July 2026 · Record updated 13 September 2026
Impact
Arbitrary code execution on GitHub Actions runners with potential exfiltration of workflow secrets including API keys and tokens
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47751
