By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Claude Code has a security problem
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Claude Code has a security problem
News

Claude Code has a security problem

News Room
Last updated: 2026/06/12 at 2:44 AM
News Room Published 12 June 2026
Share
Claude Code has a security problem
SHARE

What is noteworthy is that Mitiga Labs’ discoveries are the latest, but not the only, security problem related to Claude Code’s configuration model. Check Point Research published two further security vulnerabilities in February 2026:

  • CVE-2025-59536 allowed remote code execution through malicious hooks placed in a repository’s configuration file. The code was already executed before the user even saw a trust dialog.
  • CVE-2026-21852 allowed API keys to be extracted by overriding a single environment variable. This resulted in authenticated data traffic being redirected to attacker-controlled infrastructure before a consent prompt appeared.

To exploit the vulnerabilities, all it took was opening and cloning an untrusted repository. Anthropic has closed these security gaps after Check Point disclosed them. But the pattern is the same as what Mitiga researchers encountered: configuration files that security teams treat as passive metadata actually act as active execution paths. And this mechanism continues to work because the underlying architecture enables it.

If you’ve ever heard of Adversary-in-the-Middle (AiTM) phishing, this might sound familiar. Even with AiTM attacks, credentials are not stolen directly. Instead, the attacker intervenes between the user and the legitimate service, waits for successful authentication – and then steals the session token that proves it. The Claude Code attack chain uncovered by Mitiga works in the same way – with the difference that AiTM attacks target browser sessions. The fact that it is a developer tool doesn’t make things better – on the contrary: these tools are much closer to the source code, internal APIs, cloud infrastructure and company production systems.

3 immediate aid measures for Claude Code

Meanwhile, the adoption of Anthropic’s AI assistants continues to grow. Most developers don’t think about what the scripts do with npm dependencies and local configuration files after installation. But that’s not their job – it’s that of the security team. They can rely on the following three “immediate aid” measures to secure Claude Code:

  1. Monitor ~/.claude.json for unexpected changes: This file is the linchpin of the exploit demonstrated by Mitiga. Changes to the MCP server endpoints in this file should raise alarm bells – especially if new localhost proxy addresses or unknown external endpoints are added. Most companies do not monitor configuration files at the user level in dev environments. This urgently needs to change. Mitiga experts strongly recommend treating changes to Claude code configuration, MCP server URLs and OAuth update behavior as the primary detection layer.
  2. Treat npm post-install hooks as an increased security risk: Post-install hooks that execute arbitrary code at installation time are a known risk class in the supply chain, yet the issue is not consistently addressed in developer environments. It is recommended to check what is running in the dev pipelines while installing packages. It is also worth considering introducing a fundamental review for packages with post-install scripts – not only with regard to Claude Code, but developer tools in general.
  3. Audit and rotate OAuth tokens for Claude Code integrations: Developers who connect Claude Code to Jira, Confluence, GitHub, or another SaaS platform create OAuth tokens that persist across sessions. If these tokens were active during a period in which a malicious package was installed, they should be treated as potentially compromised – and replaced. It is also advisable to check the audit logs on the provider side for the activity patterns described. It should also be noted that, according to Mitiga, token rotation alone cannot break the attack chain if the malicious hook is still present. In this case, this ensures that the configuration is reinitialized and new tokens are captured during the next update. To fix the problem, the hook must first be removed and the configuration cleaned.

An honest assessment

Anthropic’s response to Mitiga Labs’ disclosure follows a logic that security experts are familiar with but will probably largely reject. Finally, agreeing to install a package does not constitute consent for it to rewrite an AI tool’s routing configuration and intercept SaaS credentials. If one were to follow Anthropic’s argument, the entire burden of supply chain security would be shifted to the developers. This is not a sensible security model.

The previously patched vulnerabilities revealed by Check Point make it clear that Anthropic is very responsive if the problem is presented correctly. It remains to be seen whether a patch will follow for the attack path described by Mitiga. The fact is: This attack chain works today.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article AI price war: OpenAI is said to want to drastically reduce ChatGPT prices – Anthropic could follow AI price war: OpenAI is said to want to drastically reduce ChatGPT prices – Anthropic could follow
Next Article You have to crank this AI gadget yourself: what the makers want to show with it You have to crank this AI gadget yourself: what the makers want to show with it
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

You have to crank this AI gadget yourself: what the makers want to show with it
You have to crank this AI gadget yourself: what the makers want to show with it
Software
AI price war: OpenAI is said to want to drastically reduce ChatGPT prices – Anthropic could follow
AI price war: OpenAI is said to want to drastically reduce ChatGPT prices – Anthropic could follow
Gadget
Tools for Humanity, Sam Altman’s other project, is being fired in the midst of OpenAI’s rise
Tools for Humanity, Sam Altman’s other project, is being fired in the midst of OpenAI’s rise
Computing
on which channel to watch the match? 🔴
on which channel to watch the match? 🔴
Mobile

You Might also Like

Penetration test: Once a year is not enough
News

Penetration test: Once a year is not enough

6 Min Read
OpenAI considers significant price cuts | Computer Week
News

OpenAI considers significant price cuts | Computer Week

1 Min Read
AI care steals more than 6 hours per week from employees
News

AI care steals more than 6 hours per week from employees

4 Min Read
What is Lateral Leadership? | Computer Week
News

What is Lateral Leadership? | Computer Week

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?