// ClaudeHIGH
Security firm Tenet disclosed a vulnerability in Claude Code allowing remote hijacking through poisoned error logs. When Claude Code is connected to external tools via MCP protocol, attackers can inject fake bug reports to execute arbitrary commands on a developer's machine using their credentials. Tenet demonstrated an 85% success rate across 100+ agents in controlled testing, affecting developers using MCP integrations with error trackers and project management platforms.
// Get alerts for Claude