AE-CFMQS0WN
Coding agent's overly broad safe-command allowlist lets injected instructions read a file and send it over the network without confirmation
PROMPT INJECTIONseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
An overly broad default allowlist of commands treated as safe let the agent read a file and then send its contents over the network without triggering confirmation prompts. Exploitation required untrusted content in the agent's context window.
- Framework / agent
- Claude Code (@anthropic-ai/claude-code) · terminal coding agent
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code — https://github.com/anthropics/claude-code, retrieved 2026-09-29
Symptoms
- File contents can be read and sent over the network without any confirmation prompt
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-CFMQS0WN. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.