Fetching from the wire…
Security2026-03-19 · source-backed
Check Point Research disclosed that ANTHROPIC_BASE_URL in a repository's .claude config can redirect all API traffic — including full authorization headers — to an attacker-controlled server before the user reads a trust dialog, exfiltrating API keys in plaintext. A second vector abuses Hook automation to execute arbitrary shell commands the instant Claude Code opens an untrusted project. Defense: treat .claude/ project files like executable code in your threat model. Never open unreviewed repos in Claude Code. Check Point Research
Each link below shares sources, entities, or timing with this story.
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell comm...
Check Point Research disclosed that Claude Code's .claude/settings.json hooks can be weaponized in untrusted repos to execute arbitrary shell commands and exfiltrate Anthropic API keys by redirecting ANTHROPIC_BASE_URL to an attacker-controlled MitM proxy (Check Point). Both C...
Three attack vectors: (1) Hooks-based RCE via .claude/settings.json executing shell commands on SessionStart without confirmation, (2) MCP consent bypass via repo-controlled config auto-approving all servers, (3) API key exfiltration via ANTHROPIC_BASE_URL pointing to attacker...
CVE-2025-59536 (CVSS 8.7): malicious hooks in a cloned repo's .claude/settings.json execute shell commands at session startup before security dialogs appear. MCP consent bypass: .mcp.json with enableAllProjectMcpServers auto-approves rogue servers. CVE-2026-21852 (CVSS 5.3): o...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
Go rotate a key. I'll wait. Claude Code 2.1.246, released August 25, lists this in its changelog: a fix for "telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL); a credential is now only sent to its own hos...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.