ThreatCluster

Claude Code AI Reads Sensitive Files Despite Restrictions

First seen 29 Jan 2026, 10:28 UTC Theregister 18

Article Content

Browse articles
ThreatCluster

Anthropic's Claude Code AI has been reported to access sensitive information, including passwords and API keys, from .env files that are meant to be restricted. This issue arises when developers fail to prevent these files from being uploaded to public repositories, leading to potential data exposure.