All Incidents
Critical Vulnerability in Claude Code: Just Opening a Project Lets Hackers Execute Commands Through Anthropic's AI
BreakingMAR 04, 2026BREACH

Critical Vulnerability in Claude Code: Just Opening a Project Lets Hackers Execute Commands Through Anthropic's AI

Check Point researchers discovered a critical flaw in Claude Code, Anthropic's AI coding assistant. A specially crafted repository could execute shell commands or malicious actions immediately when opened, bypassing a core security control designed to prevent execution until explicit user trust. The AI ran hidden code from untrusted projects before any user confirmation. No click required. No permission asked. Just open the file and the AI does the attacker's bidding.

HOFFICIALHITL Score
HITL Score0/100
Why this matters to youNo jargon — just what it means

Think of a helper app that's supposed to ask 'are you sure?' before it ever does anything risky on your computer — that little permission box is the whole point. Researchers found that with Anthropic's AI coding helper, just opening a project file could make it run hidden commands right away: no box, no warning, no click from you. The safety gate built to stop exactly this simply didn't fire.

Here's why that's a big deal: the protection wasn't broken by some genius hacker. A booby-trapped project could do an attacker's bidding the moment it was opened, before you ever agreed to a thing.

So how does it touch you? If you or someone you trust uses tools like this, opening one wrong shared file could hand a stranger the keys to the whole machine — your work, your passwords, your data — without you ever clicking 'yes.' The lock was there. It just didn't catch.

🖤 Explained by Babycakes.
Read the full source →
Source: SOURCE