Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
ID: 453aa247-1e8e-57f6-89bd-ab7d7e7fc438
STIX ID: report--453aa247-1e8e-57f6-89bd-ab7d7e7fc438
Feed Name: Security Ledger
Threat Score
Tego AI disclosed a vulnerability in Anthropic’s Claude Code where a repository can include a symlink or settings file that causes the tool to read files outside the cloned project and send their contents to the model endpoint without user-visible approval, effectively enabling silent data exfiltration; the report argues the ‘trust this folder’ dialog is an inadequate security boundary and documents the issue against Claude Code v2.1.x.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
