Theregister Claude Code Vulnerability Allows Bypass of Safety Rules via Subcommand Injection
Article Content
- •Claude Code's security rules can be bypassed with over 50 subcommands.
- •The vulnerability allows for prompt injection attacks, posing risks in automated environments.
- •Anthropic has an internal fix available but has not released it publicly.
A vulnerability in Claude Code allows the AI to bypass its deny rules when presented with a chain of over 50 subcommands. Discovered by Adversa, a Tel Aviv-based security firm, this flaw exposes the AI to prompt injection attacks, potentially enabling unauthorized actions like executing network requests via curl. The issue arises from a hard cap of 50 security subcommands, beyond which Claude Code defaults to asking for user permission. This oversight was not anticipated for AI-generated commands, leading to a proof-of-concept attack where a malicious command was constructed to exploit this limitation. The risk is particularly high in automated environments, such as CI/CD pipelines, where human oversight may be lacking. Anthropic has developed an internal fix but has not yet released it publicly. The vulnerability raises significant regulatory and compliance concerns if left unaddressed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…