"The Harness Was the Vulnerability, Not the Model"—A Single GitHub Issue Simultaneously Vulnerable to Claude Code, Gemini CLI, and Codex
A research finding, announced at Black Hat USA 2026 and gaining renewed attention in September, reveals a vulnerability discovered by Elad Meged, a researcher at security firm Novee Security. This vulnerability allows an account with no repository privileges to access sensitive information within the CI (Continuous Integration) execution environments of Anthropic, Google, and OpenAI's AI coding agents simply by posting a single GitHub issue. As an engineer, I want to carefully examine this research finding, centered on the concept of "harness."
Separating "Model Decisions" from "Harness Design"
The most important concept in this research is the term "harness." Meged explains it as "the code between the model and the real world." An AI coding agent is not simply a system where a language model returns a response; it only functions as a practical agent when various "pipes" such as permission management, tool invocation paths, sandbox (isolation environment) control, shared workspaces, and execution environments are combined around the model.
The three vulnerabilities discovered this time all existed in this "pipe" section. In other words, the AI model itself did not make a malicious decision; rather, there was an oversight in the design surrounding the model.
"Inconsistent String Interpretation" that Permeated Claude Code
The problem found in Anthropic's "Claude Code" (CVE-2026-54316) stemmed from a subtle discrepancy where the same string was interpreted differently during command validation and actual execution. Claude Code's command validation function removes text enclosed in single quotes before executing 23 check items. While this is correct behavior for bash (the shell), the attack code embedded in the value of git's `--receive-pack` flag slipped through this removal process and was interpreted directly by git at runtime.
Even more troublesome is the "information exfiltration route" used to exploit this vulnerability. Researchers exploited a feature of Hugging Face, for which Claude Code already had authorized access, using the publicly available "download count" counter as a hidden communication channel. This was an extremely sophisticated method, encoding the API key character by character in the form of increases and decreases in the download count before sending it.
Gemini CLI's "Perfect CVSS Score" Severity
The vulnerability found in Google's Gemini CLI (CVE-2026-12537) was even more serious. The "automatic workspace trust" mechanism in headless mode (automatic execution without screen display) combined with a design flaw where the allow list was "checked during registration but not enforced during execution" allowed the parent process's environment variables to be read through the Linux `/proc` filesystem. This vulnerability was given a perfect CVSS score of 10.0.
OpenAI Codex maintains "sandbox is working as specified"
OpenAI's response differed from the other two companies. In response to the researchers' report, OpenAI maintained that its sandbox "worked exactly as documented," and stated that no patch or CVE number was assigned to the Codex discovery in the product version. This incident highlights that the criteria for evaluating the severity of vulnerabilities can vary from company to company.
The same pattern spreading across "over 100 public repositories"
Another noteworthy aspect of this investigation is the Cloud Security Alliance's analysis. Similar configuration issues have been found in over 100 public repositories. Many of these repositories reportedly copied the official reference implementations (reference workflows) provided by Anthropic, Google, and OpenAI.
In other words, the vulnerability discovered was not limited to a single repository, but was inherent in the vendor's default settings themselves, and the same risk was spread to countless projects that adopted those settings without modification. The underlying structural problem (string-level validation differing from actual shell and file system interpretation) is said to be common to similar vulnerabilities reported in the past, such as "Clinejection," "GhostCommit," and "GuardFall."
Responses from Each Company and the Fact That It Has Already Been Fixed
Fortunately, at the time of the Black Hat announcement, the vulnerabilities in both Google and Anthropic's systems had already been patched. The Gemini CLI was fixed in version 0.39.1, and Claude Code in version 2.1.163. Google evaluated this report through its vulnerability bounty program and acknowledged the work of Meged and Dan Rishichikin of Pillar Security. Anthropic also released a patch and updated its security guidance, adding a warning about the possibility of content sanitizers being bypassed.
What Engineers Should Consider
The lesson from these findings is clear. When evaluating the security of an AI coding agent, it's insufficient to only look at the model's ability to reject dangerous instructions. Rather, the vulnerabilities that are often overlooked lie in the surrounding implementation (harness)—how the agent actually invokes tools, manages permissions, and configures the sandbox.
For engineers who have integrated or are planning to integrate AI coding agents into their CI/CD pipelines, this incident serves as a concrete call to action: "Re-audit all automated workflows that can be triggered externally." Instead of unconditionally trusting the default settings provided by the vendor, it's worth taking the time to manually verify what permissions and access scope they actually have in your environment.