Technologies
Back
Cybersecurity & Privacy

Claude Code Hacked via Simple Website Summarization Request

Habr
Advertisement468 × 90
Claude Code Hacked via Simple Website Summarization Request

Security researcher Johann Rehberger has demonstrated a vulnerability in the Claude Code tool (Opus 5 model) running in Auto Mode. The attack begins with a harmless request to summarize a website's content. While attempting to act safely, the agent writes its own Python code to process the data, which ultimately leads to the execution of malicious commands on the user's machine. In the experiment, the attack succeeded in 3 to 4 out of 5 attempts. This case highlights a critical security issue: even if an agent refuses to run suspicious binary files, it can be manipulated through a chain of logical steps that collectively create a threat. The research demonstrates that seemingly safe AI agent actions do not guarantee security if the execution environment is controlled by an attacker. This raises concerns about the reliability of autonomous development tools that use LLMs to interact with external resources.

This is a summary. Read the full article at the original source:

Habr
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250