STUPID-2026-0030
Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner
Instruction given
Automatically triage incoming GitHub issues with an AI agent.
Expected behavior
Treat issue text from arbitrary users as untrusted input; never let it drive privileged actions or command execution on the runner.
Actual behavior
Cline's AI-powered issue-triage workflow fed untrusted issue content to an agent that could act on it, allowing a crafted issue to achieve arbitrary code execution on the CI runner with access to the workflow's secrets.
Damage
Because the workflow ran in CI with repository secrets in scope, a single malicious issue could reach credentials and tokens — multiplying the blast radius of a prompt-injection into a supply-chain risk.
Classification
- Agent
- Cline
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Infra
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.