Fetching from the wire…
Top 5 · 2026-02-25 · source-backed
CVE-2025-59536 (CVSS 8.7): malicious hooks in a cloned repo's .claude/settings.json execute shell commands at session startup before security dialogs appear. MCP consent bypass: .mcp.json with enableAllProjectMcpServers auto-approves rogue servers. CVE-2026-21852 (CVSS 5.3): overriding ANTHROPIC_BASE_URL in project config redirects all API traffic — including plaintext auth headers — to attacker-controlled servers on startup with zero user interaction. All patched. Action: Never open untrusted repos without reviewing .claude/ directory contents. (Check Point Research, The Hacker News)
Each link below shares sources, entities, or timing with this story.
Claude Code uses MCP / Shared entities / Same source / Shared topic
Linked by a graph relationship (Claude Code uses MCP); both cover Action, API Key Exfiltration, Check Point Research, CVE; cite the same source (Check Point Research).
Claude Code uses MCP / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (Claude Code uses MCP); both cover Check Point Research, CVE, Never; cite the same source (Check Point Research).
Linked by a graph relationship (Claude Code uses MCP); both cover Check Point Research, CVE; cite the same source (Check Point Research).
Claude uses MCP / Shared entities / Same source / Shared topic / What happened next / Tension
Linked by a graph relationship (Claude uses MCP); both cover Check Point Research, CVE, Never; cite the same source (Check Point Research).
Claude uses MCP / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Claude uses MCP); both cover Action, MCP, The Hacker News; reported by the same outlet (thehackernews.com).
Microsoft supports MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover Action, CVE, CVSS, MCP; overlapping topics (action, attack).
Claude uses MCP / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Claude uses MCP); both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com).
Cloudflare supports MCP / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Cloudflare supports MCP); both cover CVE, CVSS, MCP; reported by the same outlet (thehackernews.com).