
Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval
A newly disclosed security issue in Anthropic’s Claude Code could allow a malicious pull request to execute attacker-controlled commands on a developer’s workstation simply by opening the AI coding assistant inside a previously trusted repository. The issue stems from how project-scoped Model Context Protocol (MCP) configurations are loaded after a repository or workspace has been […]
The post Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval appeared first on Cyber Security News.