Anthropic Claude Code’s security flaws expose devices to silent hacking, triggered from remote code execution

Security researchers claim to have uncovered three security vulnerabilities in Claude Code, Anthropic’s command-line AI tool. These flaws could have allowed attackers to execute code remotely on a developer’s machine or steal sensitive API keys. According to a Check Point report, company’s researchers found and reported all three flaws to Anthropic, which issued fixes for all and CVEs for two. While Anthropic fixed the security flaw, researchers say that the issues illustrate a worrisome supply chain threat as enterprises incorporate AI coding tools like Claude into their development processes and essentially turn configuration files into a new attack surface.

The attack vector reportedly relied on a supply chain strategy wherein hackers could inject malicious configurations into public repositories, then simply wait for a developer to clone and open the compromised project. “The ability to execute arbitrary commands through repository-controlled configuration files created severe supply chain risks, where a single malicious commit could compromise any developer working with the affected repository,” Check Point researchers Aviv Donenfeld and Oded Vanunu said in the report.

The three security vulnerabilities are said to stem from Anthropic Claude’s design, which is intended to make it easier for development teams to collaborate. The AI coding tool enables this by embedding project-level configuration files (.claude/settings.json file) directly within repositories, so that when a developer clones a project, they automatically apply the same settings used by their teammates.

Report says that any contributor with commit access can modify these files. The researchers found that cloning and opening a malicious repository sometimes allowed them to bypass built-in safeguards and trigger hidden commands and execute malicious code.

Abusing Hooks for RCE

The first flaw involved the abuse of Claude’s Hooks feature. Designed to run user-defined shell commands at specific points in the tool’s lifecycle, Hooks were intended to automate routine tasks.

However, because these hooks are defined in the .claude/settings.json file—which is part of the repository—an attacker with commit access could embed malicious shell commands into a project. When an unsuspecting developer opened the project, Claude would execute these commands automatically without requesting permission.

“An attacker could configure the hook to execute any shell command—such as downloading and running a malicious payload,” the researchers warned, demonstrating the flaw by remotely launching a reverse shell on a victim’s machine. Check Point reported the malicious hooks flaw to Anthropic on July 21, 2025, and the AI maker implemented the final fix about a month later, publishing this GitHub Security Advisory GHSA-ph6w-f82w-28w6 on August 29.

MCP consent bypass bug

The second vulnerability allowed for Remote Code Execution (RCE) by circumventing the Model Context Protocol (MCP) safety prompts. While Anthropic had implemented warnings requiring user approval before running external MCP servers, researchers discovered a workaround.

By manipulating two specific repository-controlled settings, the team was able to override these safeguards, causing malicious commands to execute the moment Claude was launched—before the user could even see a trust dialog. This bypass (CVE-2025-59536) essentially rendered the tool’s security prompts useless against a crafted repository.

Redirecting traffic to steal API Keys

The final vulnerability targeted the developer’s credentials. Researchers found they could manipulate the ANTHROPIC_BASE_URL variable within a project’s configuration. Attackers can exploit the third flaw for API key theft. By redirecting this endpoint to an attacker-controlled server, all of Claude’s API traffic—including the plaintext authorization header containing the user’s API key—was exposed.

The researchers configured ANTHROPIC_BASE_URL to route through their local proxy, and watched all Claude Code’s API traffic in real time. Every one of Claude’s calls to Anthropic servers “included the authorization header – our full Anthropic API key, completely exposed in plaintext,” they wrote.

An attacker could abuse this trick to redirect traffic and steal a developer’s active API key. It’s important because the API includes a feature called Workspaces to help developers manage multiple Claude deployments by allowing multiple API keys to share access to the same cloud-based project files. Files are connected to the workspace – not the single key – and any API key belonging to the workspace also has visibility into any of the workspace’s stored files.

Latest

India needs digital identity for every device and stronger AI-led cyber defence to curb threats: Experts

With the rapid expansion of the digital ecosystem and rising cyber threats, experts have called for creating a digital identity for every device and strengtheni

Turkish parliament passes bill to restrict social media access for under-15s

Turkish parliament passes bill to restrict social media access for under-15s

One Tech Tip: Logging on at a cafe? Privacy and security guidelines for remote workers

One Tech Tip: Logging on at a cafe? Privacy and security guidelines for remote workers

OpenAI launches workspace agents that can do your work across third-party apps

OpenAI has launched new workspace agents for ChatGPT enterprise users. The company says that these agents, that run on its coding platform Codex, can do the wor

A robot is beating human pros at table tennis. Its maker calls it a milestone for machines

A robot is beating human pros at table tennis. Its maker calls it a milestone for machines

Topics

Do Shardul Thakur qualify as a concussion sub when Mitchell Santner didn’t get hit on head in MI vs CSK? Rules explained

Mumbai Indians' Shardul Thakur being named as a concussion replacement for Mitchell Santner has caused controversy in IPL 2026.

Ritchie allows HR on first big league pitch, then leads Braves over Nats 7-2 for 8th win in 9 games

Ritchie allows HR on first big league pitch, then leads Braves over Nats 7-2 for 8th win in 9 games

Musk sounds cautious tone on robotaxis amid slower-than-expected rollout 

TESLA-ROBOTAXI/ (PIX):Musk sounds cautious tone on robotaxis amid slower-than-expected rollout 

Targets marked: Israel signals major Iran strike, awaits US green light

Israel says it is ready to resume war on Iran, with targets identified, but is awaiting US approval, as tensions rise and regional risks grow amid stalled diplo

Mass shooting at Mall of Louisiana leaves 10 injured, police lock down building

Authorities said the violence was not random. According to Morse, the incident began when two groups got into an argument near the food court, which escalated i

Stranger Things: Tales From ’85 to release today: Animated spin-off returns to Hawkins with new mystery

The universe of Stranger Things is expanding with its first animated spin-off, Stranger Things: Tales From ’85, set to premiere on Netflix today. The series r

India needs digital identity for every device and stronger AI-led cyber defence to curb threats: Experts

With the rapid expansion of the digital ecosystem and rising cyber threats, experts have called for creating a digital identity for every device and strengtheni

UN experts raise alarm over forced conversions and marriages of minority girls in Pakistan

Experts mentioned that in 2025, around 75 per cent of the women and girls affected by forced conversion through marriage in Pakistan were Hindus, while 25 per c
spot_img

Related Articles

Popular Categories

spot_imgspot_img