Critical Vulnerability Found in Anthropic's Claude Code Following Source Leak
A critical vulnerability has been discovered in Anthropic's Claude Code, a TypeScript application used for AI development, shortly after its source code was leaked. The vulnerability, identified by Adversa AI, involves a flaw in the permission system that can be bypassed, potentially allowing unauthorized access to developer systems. This issue arises from a performance fix that inadvertently created a security gap, enabling malicious prompt injections to bypass security checks. The leak and subsequent vulnerability highlight significant security challenges for Anthropic, as the exposed code provides insights into the application's operation, though it does not include sensitive data like model weights or customer information.