logo

Claude collaboration tools left the door wide open to remote code execution

ID: dfe13c0e-50f0-5cd8-966c-faf64dc7c3bf

STIX ID: report--dfe13c0e-50f0-5cd8-966c-faf64dc7c3bf

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-02-26

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point researchers found and reported three serious vulnerabilities in Anthropic's Claude Code that convert repository-controlled configuration files into an attack surface: (1) malicious Hooks in .claude/settings.json allowing arbitrary shell commands and RCE; (2) an MCP consent bypass that auto-approves external tool servers and enables pre-dialog command execution; and (3) an overridable ANTHROPIC_BASE_URL that exposed developers' Anthropic API keys, allowing workspace file manipulation. The issues were demonstrated with proof-of-concept videos, responsibly disclosed, and Anthropic issued fixes and CVEs (including CVE-2025-59536 and CVE-2026-21852), underscoring a significant software supply-chain risk for development workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.