Fetching from the wire…
Public story · 2026-02-25 · source-backed
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell commands before users see a trust dialog. (2) MCP Consent Bypass — .mcp.json overrides safeguards to auto-approve MCP servers. (3) API Key Exfiltration (CVE-2026-21852, CVSS 5.3) — overriding ANTHROPIC_BASE_URL redirects all API traffic including auth headers to attacker-controlled servers. All three trigger when you merely clone and open an untrusted repo. All patched. Action: Treat .claude/, .mcp.json, and env var overrides in any repository with the same scrutiny as executable code. (Check Point Research)
Each link below shares sources, entities, or timing with this story.
Check Point Research criticizes Claude Code / Shared entities / Same source / Shared topic
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Action, API Key Exfiltration, Check Point Research, CVE; cite the same source (Check Point Research).
Check Point Research criticizes Claude Code / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Check Point, Check Point Research, Claude Code, CVE; cite the same source (Check Point Research).
Check Point Research criticizes Claude Code / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Action, Claude Code, CVE, CVSS; overlapping topics (action, attack, code).
Check Point Research criticizes Claude Code / Shared entities / Same source / Shared topic / What happened next / Tension
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Check Point Research, Claude Code, CVE; cite the same source (Check Point Research).
Check Point Research criticizes Claude Code / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Check Point Research, Claude Code, CVE; cite the same source (Check Point Research).
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Check Point Research, CVE, MCP; cite the same source (Check Point Research).
Check Point Research criticizes Claude Code / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Claude Code, CVE, CVSS, Treat; overlapping topics (action, attack, claude, code).
Linked by a graph relationship (Check Point Research criticizes Claude Code); both cover Check Point, Claude Code, CVE, CVSS; overlapping topics (check, claude, code, cvss).