Claude collaboration tools left the door wide open to remote code execution
ID: dfe13c0e-50f0-5cd8-966c-faf64dc7c3bf
STIX ID: report--dfe13c0e-50f0-5cd8-966c-faf64dc7c3bf
Feed Name: The Register (Security)
Check Point researchers found and reported three serious vulnerabilities in Anthropic's Claude Code that convert repository-controlled configuration files into an attack surface: (1) malicious Hooks in .claude/settings.json allowing arbitrary shell commands and RCE; (2) an MCP consent bypass that auto-approves external tool servers and enables pre-dialog command execution; and (3) an overridable ANTHROPIC_BASE_URL that exposed developers' Anthropic API keys, allowing workspace file manipulation. The issues were demonstrated with proof-of-concept videos, responsibly disclosed, and Anthropic issued fixes and CVEs (including CVE-2025-59536 and CVE-2026-21852), underscoring a significant software supply-chain risk for development workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
