Skip to content
Claude Code Vulnerability Allows Bypass of Safety Rules via Subcommand Injection

Claude Code Vulnerability Allows Bypass of Safety Rules via Subcommand Injection

First seen 1 Apr 2026, 23:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 2, 2026 at 23:00 UTC
  • Claude Code's security rules can be bypassed with over 50 subcommands.
  • The vulnerability allows for prompt injection attacks, posing risks in automated environments.
  • Anthropic has an internal fix available but has not released it publicly.

A vulnerability in Claude Code allows the AI to bypass its deny rules when presented with a chain of over 50 subcommands. Discovered by Adversa, a Tel Aviv-based security firm, this flaw exposes the AI to prompt injection attacks, potentially enabling unauthorized actions like executing network requests via curl. The issue arises from a hard cap of 50 security subcommands, beyond which Claude Code defaults to asking for user permission. This oversight was not anticipated for AI-generated commands, leading to a proof-of-concept attack where a malicious command was constructed to exploit this limitation. The risk is particularly high in automated environments, such as CI/CD pipelines, where human oversight may be lacking. Anthropic has developed an internal fix but has not yet released it publicly. The vulnerability raises significant regulatory and compliance concerns if left unaddressed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 171d ago How this analysis works

Timeline

2026-04-01
Adversa reports vulnerability in Claude Code
2026-04-01
Proof-of-concept attack demonstrated by Adversa
2026-04-01
Anthropic acknowledges internal fix for the vulnerability

More articles in this cluster (9)