Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
ID: e4bc37fe-e1e3-564f-99ef-a33bbedaeadc
STIX ID: report--e4bc37fe-e1e3-564f-99ef-a33bbedaeadc
Feed Name: securityonline.info
Tego AI disclosed a vulnerability in Anthropic’s Claude Code agent where a repository file (e.g., CLAUDE.md) using symbolic links can cause the agent to follow the link to files outside the project and include their contents in the very first model request without a clear approval prompt, potentially exfiltrating sensitive local files; the report also notes repo-committed settings can redirect the agent’s outbound endpoint. Tego tested the behavior on Claude Code v2.1.x, reported it to Anthropic (closed as Informative), and emphasizes the broader authorization risk of a single “trust this folder” decision in AI coding agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
