logo

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

ID: 453aa247-1e8e-57f6-89bd-ab7d7e7fc438

STIX ID: report--453aa247-1e8e-57f6-89bd-ab7d7e7fc438

Feed Name: Security Ledger

Threat Score
60/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

...
...

Tego AI disclosed a vulnerability in Anthropic’s Claude Code where a repository can include a symlink or settings file that causes the tool to read files outside the cloned project and send their contents to the model endpoint without user-visible approval, effectively enabling silent data exfiltration; the report argues the ‘trust this folder’ dialog is an inadequate security boundary and documents the issue against Claude Code v2.1.x.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.