Claude AI Security Vulnerabilities Exposed in New Report
Recently, the cybersecurity firm Adversa revealed a critical security flaw in the AI development tool Claude Code, created by Anthropic. Researchers discovered that when the AI tool processes an excessive number of sub-commands simultaneously, its built-in security safeguards can fail.
The core of the problem is a hard-coded limit within the system. It internally uses a variable named "Maximum Safe Check Sub-Commands," which is capped at 50.

A simple overflow attack can bypass its defenses
Under normal conditions, Claude Code is designed to automatically block high-risk operations like network requests. However, once a chain of instructions surpasses 50 items, the system switches from "automatic denial" to "requesting user approval."
Attackers can exploit this by embedding lengthy instruction chains within malicious code libraries, tricking the AI into running dangerous commands. While the system displays a warning prompt, developers in the flow of long work sessions often click "allow" out of habit, potentially leading to a security breach.
Security experts recommend applying the patch immediately
Experts warn that this "safety check failure" vulnerability carries substantial risk in automated CI/CD pipelines. In non-interactive modes, programs might default to skipping permission prompts and grant execution rights to the AI directly.
Related article
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo
OpenAI, Anthropic Vie for Market Share Despite Revenue Shortfalls
Despite recent reports suggesting OpenAI missed revenue targets, creating pressure on tech stocks this Tuesday, private AI lab investors remain resilient. Seasoned backers have confirmed they will not reduce investment despite negative media coverage
California AV Compliance: A New Era of Tickets, Geofences, and 1M Miles
Guident operates an AuveTech shuttle in South Florida, managing a four-mile route in West Palm Beach and a one-mile route in Boca Raton using its remote monitoring technology. | Credit: GuidentCalifornia is redefining the regulatory landscape for dri
Related Special Topic Recommendations
Comments (0)
0/500
Recently, the cybersecurity firm Adversa revealed a critical security flaw in the AI development tool Claude Code, created by Anthropic. Researchers discovered that when the AI tool processes an excessive number of sub-commands simultaneously, its built-in security safeguards can fail.
The core of the problem is a hard-coded limit within the system. It internally uses a variable named "Maximum Safe Check Sub-Commands," which is capped at 50.

A simple overflow attack can bypass its defenses
Under normal conditions, Claude Code is designed to automatically block high-risk operations like network requests. However, once a chain of instructions surpasses 50 items, the system switches from "automatic denial" to "requesting user approval."
Attackers can exploit this by embedding lengthy instruction chains within malicious code libraries, tricking the AI into running dangerous commands. While the system displays a warning prompt, developers in the flow of long work sessions often click "allow" out of habit, potentially leading to a security breach.
Security experts recommend applying the patch immediately
Experts warn that this "safety check failure" vulnerability carries substantial risk in automated CI/CD pipelines. In non-interactive modes, programs might default to skipping permission prompts and grant execution rights to the AI directly.
DeepMind CEO Hassabis: I sleep six hours a day, usually feel energetic around 1 a.m.
Fortune recently featured an interview with Demis Hassabis, CEO of Google DeepMind, revealing his unconventional approach to rest and productivity. Hassabis disclosed that he sleeps very little, structuring his waking hours into two distinct work blo
OpenAI, Anthropic Vie for Market Share Despite Revenue Shortfalls
Despite recent reports suggesting OpenAI missed revenue targets, creating pressure on tech stocks this Tuesday, private AI lab investors remain resilient. Seasoned backers have confirmed they will not reduce investment despite negative media coverage





Home






