Check Point Research found that a cloned repository's Claude Code configuration could run hooks, start MCP servers before the user approved them, and redirect API traffic so the user's Anthropic API key was sent to an attacker (CVE-2025-59536, CVE-2026-21852). Anthropic fixed the issues between August and December 2025 by deferring execution and API calls until after the trust dialog.
Why it matters
Repository-level agent configuration is executable attack surface that triggers when a developer simply opens a project.
Key facts
As stated in the sources, with where to find them.
- Hooks issue reported 2025-07-21 and fixed 2025-08-26 (advisory GHSA-ph6w-f82w-28w6); MCP consent bypass reported 2025-09-03, fixed 2025-09-22, CVE-2025-59536 published 2025-10-03; API-key exfiltration reported 2025-10-28, fixed 2025-12-28, CVE-2026-21852 published 2026-01-21.Timeline and Disclosure
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Apr 15, 2026
Aug 5, 2025
Apr 1, 2025
Mar 30, 2025
Sep 25, 2025
Sep 16, 2026