{"id":657531,"date":"2026-05-08T10:40:39","date_gmt":"2026-05-08T10:40:39","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/657531\/"},"modified":"2026-05-08T10:40:39","modified_gmt":"2026-05-08T10:40:39","slug":"claude-code-trust-prompt-can-trigger-one-click-rce","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/657531\/","title":{"rendered":"Claude Code trust prompt can trigger one-click RCE"},"content":{"rendered":"<p class=\"kicker \" style=\"\">security<\/p>\n<p class=\"subtitle \" style=\"\">Security biz Adversa AI argues users of AI tools need clearer warnings<\/p>\n<p>How explicit does the maker of a footgun need to be about the product&#8217;s potential to shoot you in the foot?<\/p>\n<p>That&#8217;s essentially the question security firm Adversa AI is asking with the disclosure of a one-click remote code execution attack via an MCP server in Claude Code, Gemini CLI, Cursor CLI, and Copilot CLI.<\/p>\n<p>The TrustFall proof-of-concept attack demonstrates how a cloned code repository can include two JSON files (.mcp.json and .claude\/settings.json) that open the door to an attacker-controlled Model Context Protocol (MCP) server.<\/p>\n<p>MCP servers make tools, configuration data, schemas, and documentation available in a standard format to AI models via JSON.<\/p>\n<p>The vulnerability arises from inconsistent restrictions governing the scope of settings: Anthropic blocks some dangerous settings at the project level (e.g. bypassPermissions) but not others (e.g. enableAllProjectMcpServers and enabledMcpjsonServers). The JSON files simply enable those settings.<\/p>\n<p>&#8220;The moment a developer presses Enter on Claude Code&#8217;s generic &#8216;Yes, I trust this folder&#8217; dialog, the server spawns as an unsandboxed Node.js process with the user&#8217;s full privileges \u2014 no per-server consent, no tool call from Claude required,&#8221; Adversa AI explains in its PoC repo.<\/p>\n<p>The likely result is a compromised system. The PoC demonstrated in this <a href=\"https:\/\/www.youtube.com\/watch?v=3kVOYQ70FVY\" rel=\"nofollow noopener\" target=\"_blank\">video<\/a>. It worked on Claude Code CLI v2.1.114, as of May 2. Other agent CLIs are also said to be affected, but specific PoCs have not been published.<\/p>\n<p>&#8220;It&#8217;s the third CVE in Claude Code in six months from the same root cause (project-scoped settings as injection vector),&#8221; Alex Polyakov, co-founder of Adversa AI, told The Register in an email. &#8220;Each gets patched in isolation but the underlying class hasn&#8217;t been finally fixed. Most developers don&#8217;t know these settings exist, let alone that a cloned repo can set them silently.&#8221;<\/p>\n<p>Anthropic, according to the security biz, contends that the user&#8217;s trust decision moves the issue outside its threat model. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-59536\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-59536<\/a> was considered a vulnerability because it triggered automatically when a user started up Claude Code in a malicious directory. TrustFall, however, is considered out of scope because the user has been presented with a dialog box and made a trust decision.<\/p>\n<p>Adversa argues that the decision is not being made with informed consent, citing a prior, more explicit warning notice that was removed in v2.1 of the Claude Code CLI.<\/p>\n<p>&#8220;The pre-v2.1 dialog explicitly warned that .mcp.json could execute code and offered three options including &#8216;proceed with MCP servers disabled,'&#8221; writes Adversa&#8217;s Sergey Malenkovich. &#8220;That informed-consent UX was removed. The current dialog defaults to &#8216;Yes, I trust this folder&#8217; with no MCP-specific language, no enumeration of which executables will spawn, and no opt-out for MCP while keeping the rest of the trust grant.&#8221;<\/p>\n<p>Then there&#8217;s the zero-click variant to consider for CI\/CD pipelines that implement Claude Code. When Claude Code is invoked in CI\/CD, that happens via SDK rather than the interactive CLI. So there&#8217;s no terminal prompt.<\/p>\n<p>Malenkovich argues that Anthropic should make three changes.\u00a0<\/p>\n<p>First, block enableAllProjectMcpServers, enabledMcpjsonServers, and permissions.allow from any settings file inside a project. The idea is that a malicious server should not be able to approve its own servers.<\/p>\n<p>Second, implement a dedicated MCP consent dialog that defaults to &#8220;deny.&#8221; And third, require interactive consent per server rather than for all servers.<\/p>\n<p>Anthropic did not respond to a request for comment. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Security biz Adversa AI argues users of AI tools need clearer warnings How explicit does the maker&hellip;\n","protected":false},"author":2,"featured_media":657532,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":["post-657531","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/657531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=657531"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/657531\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/657532"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=657531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=657531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=657531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}