logo

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

ID: 9bfd4236-0c98-55fc-b27f-59a76bdc78f8

STIX ID: report--9bfd4236-0c98-55fc-b27f-59a76bdc78f8

Feed Name: HackRead

Threat Score
60/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: CyberNewswire

...
...

Tego AI published research showing a symbolic-link-based flaw in Anthropic’s Claude Code agent: when a developer clones a repository containing a specially crafted CLAUDE.md (or linked settings file), Claude Code can follow the symlink to files outside the project and include their contents in the initial network request to the model without a clear approval prompt, enabling silent data exfiltration; the issue was reported to Anthropic (closed as Informative) and reproduces on Claude Code v2.1.x.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.