Skip to content

ai-security

Agentjacking vulnerability exposes Claude Code and Cursor to hijacking via fake error reports

Claude News

Researchers at Tenet Security found a way to compromise AI agents using the Model Context Protocol. The attack requires no malware, as the agent itself executes the attacker's code with developer privileges.

The technique relies on spoofing data in Sentry. The attacker sends a fake report with a malicious command in the Resolution field. Agents connected to Sentry via MCP interpret this text as a trusted instruction and execute it in the terminal.

In tests, the vulnerability worked 85% of the time for Claude Code and Cursor. The attack gives access to environment variables, AWS keys, and GitHub tokens. It bypasses EDR and firewalls, as the agent's actions are formally authorized by the user. Sentry addressed the issue with string filtering rather than fundamental changes.

Related stories

  1. Vulnerabilities in Claude Code plugin marketplace
  2. The .claude directory creates an attack surface in Claude Code
  3. Claude Desktop turned into a C2 agent via configuration poisoning
  4. Hackers use Claude for corporate network attacks
  5. Claude Code stores MCP OAuth tokens in plaintext on Linux
  6. Miasma attack targets AI assistant configurations

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.