Anthropic response to 1-click pwn: Shouldn't have clicked 'ok'
ID: c43dd4b5-0e57-5930-a834-fc75deb0d5cd
STIX ID: report--c43dd4b5-0e57-5930-a834-fc75deb0d5cd
Feed Name: The Register (Security)
Adversa AI disclosed a TrustFall proof-of-concept showing that malicious .mcp.json and .claude/settings.json files in cloned repositories can enable attacker-controlled MCP servers which spawn unsandboxed Node.js processes with full user privileges when a developer accepts Claude Code's generic "Yes, I trust this folder" prompt. The flaw allows one-click remote code execution (and can be invoked without interaction in CI/CD via SDK), affects multiple agent CLIs, and is exacerbated by project-scoped settings that can approve servers; Adversa recommends blocking certain settings, making MCP consent deny-by-default, and requiring per-server interactive consent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
