Close Menu
GeekPlanet

    Subscribe to Updates

    Be Geeky and subscribe to GeekPlanet for Technology, Security and Gadgets.

    What's Hot

    Tips to Secure Your Online Banking in India

    Android Privacy Controls You Should Enable Right Now

    Upcoming Budget Smartwatches in India This Quarter

    Facebook X (Twitter) Instagram
    • Privacy & Policy
    • Terms & Conditions
    • Contact US
    Facebook X (Twitter) Instagram YouTube
    GeekPlanetGeekPlanet
    AtlasVpn
    • Home
    • Gadgets
    • Entertainment
    • Cyber Security
    • How To’s & Guides
    • Reviews
    • Python
    GeekPlanet
    Home - Computer Tips & Tricks - Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines
    Computer Tips & Tricks

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Geek PlanetBy Geek Planet4 Mins Read
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Claude Code AI developer tools terminal
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Cybersecurity hacking code on terminal screen

    The AI Now Institute disclosed a proof-of-concept exploit on July 10, 2026, showing that Claude Code’s “auto-mode” feature can be tricked into running attacker-controlled code on a developer’s machine. The attack works across multiple Anthropic models and does not require any custom configuration, plugins, or MCP servers.

    How the Claude Code Exploit Works

    The vulnerability targets Claude Code CLI versions 2.1.116 through 2.1.199 running with Claude Sonnet 4.6, Sonnet 5, or Opus 4.8 in auto-mode. It also affects Codex CLI 0.142.4 with GPT-5.5 in auto-review mode. In both cases, the AI classifier that approves shell commands it considers safe is the weak point.

    Researchers at AI Now installed the agent on a Linux host, placed a modified version of the geopy Python library on disk, and issued a single natural-language instruction to perform security testing on that code. The agent explored the repository, read documentation that framed a helper script as useful for security checks, inspected a binary that appeared backed by matching source code, and executed it because the documentation aligned with the review task. The binary then ran attacker-controlled code on the host.

    Neither the script nor the binary was called by any legitimate library function, which kept traditional static analysis tools quiet. When researchers later asked the underlying models whether prompt injection attempts existed in the source, Claude Sonnet 4.6 and GPT-5.5 both failed to flag the malicious material.

    The Attack Transfers Across Models

    The technique works without modification across the tested models. In some runs, Sonnet 5 or Opus 4.8 flagged that certain files did not belong to the upstream project, yet still proceeded to execute the commands. Researchers also succeeded with variations that placed instructions in CLAUDE.md or agent.md files, which the agents treat as persistent project context.

    CVE-2025-59536 (CVSS 8.7 High) covers the remote code execution via pre-trust hook execution and MCP consent bypass. CVE-2026-21852 addresses the companion API token exfiltration through project files. A third vulnerability, CVE-2026-24887, covers the bypass of confirmation prompts in Claude Code.

    Real-World Attack Scenarios

    Two realistic scenarios map directly onto everyday developer workflows. First, a library maintainer can embed undisclosed instructions that steer coding agents. Previous public examples showed agents instructed to delete test suites in legitimate-looking codebases. Second, a supply-chain compromise of a popular package can insert the same material. Automated dependency updates and CI jobs that invoke an agent to review the new version then become the trigger, and the developer never opens the poisoned files themselves.

    Sandboxing does not close the gap once the agent achieves code execution. The researchers note prior sandbox issues disclosed against Claude Code itself. An attacker who already runs code on the host can probe the sandbox, write configuration files, steal keys, or establish persistence.

    What Developers Should Do

    The AI Now Institute published a Friendly Fire repository with supporting files and a stripped, benign binary for researchers. The original payload is available only on request to AI labs and security researchers.

    Any developer workstation or CI runner that grants an agent shell access and feeds it untrusted source inherits this exposure. Teams should isolate agents on machines that hold no production secrets, no broad filesystem mounts, and no network paths to internal services. Runtime monitoring that watches agent actions, rather than just credentials, can surface anomalies like execution of a binary that nothing in the legitimate codebase references.

    Frequently Asked Questions

    What is CVE-2025-59536?

    CVE-2025-59536 is a critical vulnerability in Claude Code that allows remote code execution through pre-trust hook execution. Attackers can achieve code execution before trust dialogs appear, with a CVSS score of 8.7 (High).

    Which Claude Code versions are affected?

    Claude Code CLI versions 2.1.116 through 2.1.199 are vulnerable when running in auto-mode with Sonnet 4.6, Sonnet 5, or Opus 4.8. Codex CLI 0.142.4 with GPT-5.5 in auto-review is also affected.

    Can this exploit be used against any AI coding tool?

    The same attack worked across Claude Sonnet 4.6, Sonnet 5, Opus 4.8, and GPT-5.5 without modification. Researchers noted this is a structural property of how agentic coding tools handle untrusted text, not a model-specific bug.

    How can developers protect themselves?

    Run agents on isolated machines without production secrets or broad filesystem access. Monitor agent actions at the behavioral layer. Avoid feeding untrusted repositories to agents with shell access. Traditional static analysis and dependency pinning remain essential controls.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Geek Planet
    • Website
    • Facebook
    • X (Twitter)
    • Instagram

    Hello, tech enthusiasts! I'm Devender, your guide through the ever-evolving world of technology. With a passion for innovation and a knack for breaking down complex concepts into digestible bits, I'm here to help you navigate the digital frontier.

    Related Posts

    Tips to Secure Your Online Banking in India

    Cyber Security: Latest Updates Every Tech User Should Know August 2026

    Tips to Secure Your Online Banking in India

    Securing Your Remote Desktop: Protecting Your Home Office

    Cyber Security Threats 2026: How Indian Users Should Protect Data

    Cyber Security Threats 2026: How Indian Users Should Protect Data

    Leave A Reply Cancel Reply

    Top Posts

    Tips to Secure Your Online Banking in India

    Data Structures and Their Functions in Python

    How do I edit a sent message on WhatsApp?

    Don't Miss

    Tips to Secure Your Online Banking in India

    Follow these expert tips to keep your bank accounts safe from hackers.

    Android Privacy Controls You Should Enable Right Now

    Upcoming Budget Smartwatches in India This Quarter

    Generative AI Tools Helping Indian Startups Scale Fast

    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    TPS4
    Most Popular

    Tips to Secure Your Online Banking in India

    Data Structures and Their Functions in Python

    How do I edit a sent message on WhatsApp?

    Our Picks

    Tips to Secure Your Online Banking in India

    Android Privacy Controls You Should Enable Right Now

    Upcoming Budget Smartwatches in India This Quarter

    Subscribe to Updates

    Be Geeky and subscribe to GeekPlanet for Technology, Security and Gadgets.

    Facebook X (Twitter) Instagram Pinterest
    © 2026 GeekPlanet.in Managed by MyAdsMantra Global.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    GeekPlanet is a safe place for every tech lover and is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.