logo

Claude Code Can Be Manipulated via CLAUDE.md to Run SQL Injection Attacks

ID: f4671999-6be2-54aa-9575-7617ebe78162

STIX ID: report--f4671999-6be2-54aa-9575-7617ebe78162

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

LayerX demonstrated that Claude Code's project-level CLAUDE.md instruction file can be abused to override the model's safety guardrails, allowing the AI to perform unauthorized actions—including automated SQL injection and credential theft; researchers tested the technique in a vulnerable web app, outlined supply-chain and insider risks, and urged teams to treat CLAUDE.md files like code while awaiting a response from Anthropic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.