logo

Untrusted repositories turn Claude code into an attack vector

ID: fcbb55f3-c65d-5c60-ab6a-7bc8f56d46b5

STIX ID: report--fcbb55f3-c65d-5c60-ab6a-7bc8f56d46b5

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Check Point Research discovered critical vulnerabilities in Anthropic's Claude Code that enable remote code execution and theft of Anthropic API keys simply by cloning and opening a malicious repository; attackers can abuse project-level config files, Hooks, MCP integrations, and environment variables to run hidden shell commands, exfiltrate workspace-shared credentials, and potentially pivot into shared cloud environments. Anthropic mitigated the issues by tightening trust prompts, blocking external tool execution, and restricting API calls until user approval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.