Chronicle/Attacks & incidents

Check Point: Claude Code project files could run commands and leak API keys before trust prompt

AttackVulnerability disclosureSignificance assistant-drafted

Check Point Research found that a cloned repository's Claude Code configuration could run hooks, start MCP servers before the user approved them, and redirect API traffic so the user's Anthropic API key was sent to an attacker (CVE-2025-59536, CVE-2026-21852). Anthropic fixed the issues between August and December 2025 by deferring execution and API calls until after the trust dialog.

Why it matters

Repository-level agent configuration is executable attack surface that triggers when a developer simply opens a project.

Key facts

As stated in the sources, with where to find them.

  • Hooks issue reported 2025-07-21 and fixed 2025-08-26 (advisory GHSA-ph6w-f82w-28w6); MCP consent bypass reported 2025-09-03, fixed 2025-09-22, CVE-2025-59536 published 2025-10-03; API-key exfiltration reported 2025-10-28, fixed 2025-12-28, CVE-2026-21852 published 2026-01-21.Timeline and Disclosure

Findings that cite this record

Key questions this bears on

Sources

Related records