Anthropic quietly patches vulnerabilities in Claude Code

Security researcher Aonan Guan found a second critical flaw in five months in Claude Code's network sandbox. The bug allowed bypassing filters and sending sensitive data like GitHub tokens and cloud credentials to arbitrary external servers.
Anthropic fixed the issue in version 2.1.88 but did not publish a CVE or official security notice. The company considers the in-repo fix in sandbox-runtime sufficient, but experts criticize this approach.
The main risk is a false sense of security: users think their data is protected by the sandbox, but network boundaries are effectively absent. Experts advise treating AI agents like employees with limited access rights, not regular software.
Related stories
- One git call let a repo escape the Claude Code sandbox
- Stolen session keys are draining Claude Max accounts
- Breaking Claude Code Opus 5 Auto Mode
- Claude Opus broke four SAML libraries in a month
- Hidden China tracker pulled from Claude Code after exposé
- Auto mode let Claude Code run downloaded code in 6 of 10 tests
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
