logo

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

ID: 028f2164-f98d-5498-b4cb-0d6635a7ab3e

STIX ID: report--028f2164-f98d-5498-b4cb-0d6635a7ab3e

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: CyberNewswire

...
...

**Tego AI disclosed a vulnerability in Anthropic's Claude Code**: a repository-committed instruction file can include an @import directive pointing to a symbolic link which resolves outside the project, causing Claude Code to read external files and include their contents in the first outbound request without a visible approval or prompt. The issue can leak sensitive files (e.g., /etc/passwd) when a developer clones and trusts a repository; Tego confirmed the behavior against Claude Code v2.1.x, reported it via HackerOne in July 2026, and Anthropic closed the report as Informative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.