CVE-2026-47751

anthropics/claude-code-action: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CVE-2026-47751)

mediumEPSS 0.8%

Description

Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-controlled pull request head branches, read .mcp.json from the working directory via default setting sources, and unconditionally enabled all project MCP servers via enableAllProjectMcpServers, an attacker who opened a pull request containing a malicious .mcp.json file could achieve arbitrary code execution on the GitHub Actions runner and exfiltrate secrets available to the workflow (such as API keys and tokens) when a privileged user or an automatic trigger invoked the Claude action on the pull request. This issue is fixed in version 1.0.74, which restores .claude/ and .mcp.json from the pull request base branch before the CLI runs.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

github actionsanthropics/claude-code-action

Metrics

5.3
Source: nvd-v4
54.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-16 15:59 UTC
CWE-78, CWE-200

Weakness classes (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →
  • CWE-200Class

    Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

    cwe.mitre.org →

References & sources