Fetching from the wire…
Public story · 2026-02-25 · source-backed
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell commands before users see a trust dialog. (2) MCP Consent Bypass — .mcp.json overrides safeguards to auto-approve MCP servers. (3) API Key Exfiltration (CVE-2026-21852, CVSS 5.3) — overriding ANTHROPIC_BASE_URL redirects all API traffic including auth headers to attacker-controlled servers. All three trigger when you merely clone and open an untrusted repo. All patched. Action: Treat .claude/, .mcp.json, and env var overrides in any repository with the same scrutiny as executable code. (Check Point Research)
Each link below shares sources, entities, or timing with this story.
CVE-2025-59536 (CVSS 8.7): malicious hooks in a cloned repo's .claude/settings.json execute shell commands at session startup before security dialogs appear. MCP consent bypass: .mcp.json with enableAllProjectMcpServers auto-approves rogue servers. CVE-2026-21852 (CVSS 5.3): o...
Check Point Research disclosed that Claude Code's .claude/settings.json hooks can be weaponized in untrusted repos to execute arbitrary shell commands and exfiltrate Anthropic API keys by redirecting ANTHROPIC_BASE_URL to an attacker-controlled MitM proxy (Check Point). Both C...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
Check Point Research disclosed that ANTHROPIC_BASE_URL in a repository's .claude config can redirect all API traffic — including full authorization headers — to an attacker-controlled server before the user reads a trust dialog, exfiltrating API keys in plaintext. A second vec...
Three attack vectors: (1) Hooks-based RCE via .claude/settings.json executing shell commands on SessionStart without confirmation, (2) MCP consent bypass via repo-controlled config auto-approving all servers, (3) API key exfiltration via ANTHROPIC_BASE_URL pointing to attacker...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.