Skip to content
AnthropicGHSA-8q5r-mmjf-575q

Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Medium5.3CVE-2026-47751 · Published May 20, 2026

Due to the combination of checking out PR head branches (attacker-controlled), reading `.mcp.json` from the working directory via default setting sources, and unconditionally enabling all project MCP servers via `enableAllProjectMcpServers`, it was possible for an attacker who opened a PR containing a malicious `.mcp.json` file to achieve arbitrary code execution on the GitHub Actions runner. This could lead to exfiltration of secrets available to the workflow (such as API keys and tokens) when a privileged user triggered the Claude action on the PR. Exploiting this required the ability to open a pull request against a repository using the claude-code-action and a privileged user or automatic trigger to invoke the action on that PR. Users pinned to a vulnerable version of claude-code-action are advised to update to the latest version. Users referencing anthropics/claude-code-action@v1, anthropics/claude-code-action@beta, anthropics/claude-code-action@main, or other non-pinned tags will have received this fix already Thank you to hackerone.com/reptou for reporting this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
anthropics/claude-code-action
Product
< 1.0.741.0.74
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78, CWE-200

More Anthropic advisories

All Anthropic

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.