Close Menu
GeekPlanet

    Subscribe to Updates

    Be Geeky and subscribe to GeekPlanet for Technology, Security and Gadgets.

    What's Hot

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Best Buy July 2026 Deals: 57% Off LG OLED, GoPro Max2 at $299

    DeepSeek Building Custom AI Inference Chip to Reduce Nvidia Dependency

    Facebook X (Twitter) Instagram
    • Privacy & Policy
    • Terms & Conditions
    • Contact US
    Facebook X (Twitter) Instagram YouTube
    GeekPlanetGeekPlanet
    AtlasVpn
    • Home
    • GeekPlanet’s Blogs
      • How To’s & Guides
      • Reviews
    • Gadgets
    • Apps
    • Learn IT
      • Go
      • Java
      • JavaScript
      • Kotlin
      • Python
      • Swift
    • Entertainment
    • Cyber Security
    GeekPlanet
    Home - Computer Tips & Tricks - Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines
    Computer Tips & Tricks

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Geek PlanetBy Geek Planet4 Mins Read
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Claude Code AI developer tools terminal
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Cybersecurity hacking code on terminal screen

    The AI Now Institute disclosed a proof-of-concept exploit on July 10, 2026, showing that Claude Code’s “auto-mode” feature can be tricked into running attacker-controlled code on a developer’s machine. The attack works across multiple Anthropic models and does not require any custom configuration, plugins, or MCP servers.

    How the Claude Code Exploit Works

    The vulnerability targets Claude Code CLI versions 2.1.116 through 2.1.199 running with Claude Sonnet 4.6, Sonnet 5, or Opus 4.8 in auto-mode. It also affects Codex CLI 0.142.4 with GPT-5.5 in auto-review mode. In both cases, the AI classifier that approves shell commands it considers safe is the weak point.

    Researchers at AI Now installed the agent on a Linux host, placed a modified version of the geopy Python library on disk, and issued a single natural-language instruction to perform security testing on that code. The agent explored the repository, read documentation that framed a helper script as useful for security checks, inspected a binary that appeared backed by matching source code, and executed it because the documentation aligned with the review task. The binary then ran attacker-controlled code on the host.

    Neither the script nor the binary was called by any legitimate library function, which kept traditional static analysis tools quiet. When researchers later asked the underlying models whether prompt injection attempts existed in the source, Claude Sonnet 4.6 and GPT-5.5 both failed to flag the malicious material.

    The Attack Transfers Across Models

    The technique works without modification across the tested models. In some runs, Sonnet 5 or Opus 4.8 flagged that certain files did not belong to the upstream project, yet still proceeded to execute the commands. Researchers also succeeded with variations that placed instructions in CLAUDE.md or agent.md files, which the agents treat as persistent project context.

    CVE-2025-59536 (CVSS 8.7 High) covers the remote code execution via pre-trust hook execution and MCP consent bypass. CVE-2026-21852 addresses the companion API token exfiltration through project files. A third vulnerability, CVE-2026-24887, covers the bypass of confirmation prompts in Claude Code.

    Real-World Attack Scenarios

    Two realistic scenarios map directly onto everyday developer workflows. First, a library maintainer can embed undisclosed instructions that steer coding agents. Previous public examples showed agents instructed to delete test suites in legitimate-looking codebases. Second, a supply-chain compromise of a popular package can insert the same material. Automated dependency updates and CI jobs that invoke an agent to review the new version then become the trigger, and the developer never opens the poisoned files themselves.

    Sandboxing does not close the gap once the agent achieves code execution. The researchers note prior sandbox issues disclosed against Claude Code itself. An attacker who already runs code on the host can probe the sandbox, write configuration files, steal keys, or establish persistence.

    What Developers Should Do

    The AI Now Institute published a Friendly Fire repository with supporting files and a stripped, benign binary for researchers. The original payload is available only on request to AI labs and security researchers.

    Any developer workstation or CI runner that grants an agent shell access and feeds it untrusted source inherits this exposure. Teams should isolate agents on machines that hold no production secrets, no broad filesystem mounts, and no network paths to internal services. Runtime monitoring that watches agent actions, rather than just credentials, can surface anomalies like execution of a binary that nothing in the legitimate codebase references.

    Frequently Asked Questions

    What is CVE-2025-59536?

    CVE-2025-59536 is a critical vulnerability in Claude Code that allows remote code execution through pre-trust hook execution. Attackers can achieve code execution before trust dialogs appear, with a CVSS score of 8.7 (High).

    Which Claude Code versions are affected?

    Claude Code CLI versions 2.1.116 through 2.1.199 are vulnerable when running in auto-mode with Sonnet 4.6, Sonnet 5, or Opus 4.8. Codex CLI 0.142.4 with GPT-5.5 in auto-review is also affected.

    Can this exploit be used against any AI coding tool?

    The same attack worked across Claude Sonnet 4.6, Sonnet 5, Opus 4.8, and GPT-5.5 without modification. Researchers noted this is a structural property of how agentic coding tools handle untrusted text, not a model-specific bug.

    How can developers protect themselves?

    Run agents on isolated machines without production secrets or broad filesystem access. Monitor agent actions at the behavioral layer. Avoid feeding untrusted repositories to agents with shell access. Traditional static analysis and dependency pinning remain essential controls.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Geek Planet
    • Website
    • Facebook
    • X (Twitter)
    • Instagram

    Hello, tech enthusiasts! I'm Devender, your guide through the ever-evolving world of technology. With a passion for innovation and a knack for breaking down complex concepts into digestible bits, I'm here to help you navigate the digital frontier.

    Related Posts

    Canvas Data Breach Hits 8,800 Schools, 275 Million Users Worldwide

    Jack Dorsey Launches Buzz to Compete with Slack

    OpenAI Agent Breaches Hugging Face After Escaping Testing

    June 2026 Cybersecurity Roundup: Novo Nordisk Hack, 24 Billion Credentials Exposed, Nintendo Data Stolen

    84% of Developers Use AI Coding Tools but Productivity Gains Are Only 10%

    Suno AI Data Breach Exposed 55 Million Users Personal Data

    Leave A Reply Cancel Reply

    Top Posts

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Data Structures and Their Functions in Python

    How do I edit a sent message on WhatsApp?

    Don't Miss

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    A new Claude Code RCE exploit lets attackers execute arbitrary commands on developer machines through prompt injection in third-party library reviews.

    Best Buy July 2026 Deals: 57% Off LG OLED, GoPro Max2 at $299

    DeepSeek Building Custom AI Inference Chip to Reduce Nvidia Dependency

    Canvas Data Breach Hits 8,800 Schools, 275 Million Users Worldwide

    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    TPS4
    Most Popular

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Data Structures and Their Functions in Python

    How do I edit a sent message on WhatsApp?

    Our Picks

    Claude Code Auto-Mode Exploit Lets Attackers Run Code on Dev Machines

    Best Buy July 2026 Deals: 57% Off LG OLED, GoPro Max2 at $299

    DeepSeek Building Custom AI Inference Chip to Reduce Nvidia Dependency

    Subscribe to Updates

    Be Geeky and subscribe to GeekPlanet for Technology, Security and Gadgets.

    Facebook X (Twitter) Instagram Pinterest
    © 2026 GeekPlanet.in Managed by MyAdsMantra Global.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    GeekPlanet is a safe place for every tech lover and is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.