#cve
5 articles
CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…
CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…
A parsing mismatch in the ip-address npm package can make your agent fetch an internal cloud-metadata server it meant to block. He…
CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…
CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…