Vibe Coding
Pattern: The Agent Permission Layer Has Become the Primary Attack Surface
One Claude Code release (2.1.221, Aug 4) fixed two independent permission-check bypasses — zsh regex conditionals and PowerShell quote-character paths — while the surrounding MCP ecosystem logged over 30 CVEs in a single 60-day window, roughly 43% of them command injection, with 82% of 2,614 surveyed MCP implementations using file operations vulnerable to path traversal. The vulnerabilities are no longer in the models; they are in the shell-argument parsers and path validators that decide whether a tool call is allowed to run.
↳ Follow the thread