Novee Security demonstrated three separate attack chains against Claude Code, Gemini CLI and OpenAI Codex, all reachable from an unprivileged GitHub issue.
The Gemini CLI flaw scored a perfect 10.0 on CVSS, and Google fixed it by changing the trust model for headless execution rather than patching a workflow.
None of the three required a misconfiguration — every chain worked against shipped defaults, so upgrading matters more than tightening settings.