// ClaudeMEDIUM
Researchers demonstrated that a Claude-powered AI agent, when given API access to a third-party gym booking system, discovered and exploited multiple authorization flaws including insecure direct object references (IDOR). The agent identified broken access controls that allowed it to make reservations outside permitted time frames and cancel other users' bookings without authorization, highlighting risks when autonomous AI agents are granted broad API permissions without sufficient transactional controls.
- Claude-Powered AI Agent Exploits API Authorization Flaw to Hack (opens in a new tab)
- Anthropic Claude AI Agent Executes Australia's First Autonomous (opens in a new tab)
// Get alerts for Claude