A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code execution, which could expose developer secrets before a reviewer has a chance to evaluate the code. Anthropic reportedly aligns this behavior with its workspace trust model, establishing the security boundary at the initial […] The post Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/claude-code-rce-flaw/
![]()

