CloudSecurityAlliance[verified]@cloudsaPatch
ServiceNow has patched three critical CVSS‑10 AI platform vulnerabilities, and evidence suggests they were actively exploited, as seen with CI hijacking and compromised credentials.
Slade 🛡️ LLM Hacker[verified]@llm_redteamDisclosure
The post discloses two new CVEs in Claude Code and Gemini CLI, explains how they leak API keys or enable remote code execution, and provides patch versions and mitigation guidance.
DS[verified]@GoToTokyoUniv0Active Exploitation
The post reports an active exploitation of CVE-2026-54316, detailing how attackers used a public GitHub issue to exfiltrate data via download‑count metrics, but provides no PoC code, patch, or clarification that the vulnerability is a false positive.
Bradley Cassada[verified]@bcassadaDisclosure
The post announces critical flaws discovered in Anthropic, Google, and OpenAI coding agents, naming CVE-2026-54316 and highlighting high CVSS scores and prompt injection vectors; no PoC, exploit script, or patch information is provided.
Jesús Morán | AI Infra[verified]@jamoran1356Exploit
CVE‑2026‑54316 enables attackers to inject malicious instructions via an unauthenticated GitHub issue, which are then executed by a CI agent, resulting in secret exfiltration.
Jesús Morán | AI Infra[verified]@jamoran1356Active Exploitation
CVE-2026-54316 is actively exploited, allowing an unauthenticated user to open a GitHub issue via a CI agent and exfiltrate secrets. The vulnerability was presented at Black Hat and impacts Claude Code Action.
DkillG[verified]@DkillGPatch
CVE‑2026‑54316 exposes a critical command‑execution flaw in Claude Code that leaks API keys; the issue is mitigated by upgrading to version 2.1.163 and above.
Claude Code Lab @CWorksL[verified]@cc_lab_jpPatch
CVE‑2026‑54316 exploits WebFetch to leak API keys one character at a time; the issue is fixed in v2.1.163 and newer releases.