logo

Critical Claude Code Flaw Silently Bypasses User-Configured Security Rules

ID: 6d64577a-d6f3-57a7-8551-38c8c578ddbd

STIX ID: report--6d64577a-d6f3-57a7-8551-38c8c578ddbd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Divya

...
...

A critical flaw in Anthropic’s Claude Code allows developers’ deny rules (blocking actions like curl or rm) to be skipped when a generated compound command contains more than 50 subcommands; attackers can exploit this by hiding malicious commands at position 51 in build sequences (e.g., via poisoned repository CLAUDE.md) to exfiltrate SSH keys, cloud credentials, or API tokens. Anthropic has patched the issue in Claude Code v2.1.90, but the report warns unpatched users to restrict shell access, monitor outbound connections, and audit external repository configuration files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.