| Breaking Claude Code Opus 5 Auto Mode(embracethered.com) | |
| 394 points by Recursing 10 days ago | 119 comments | |
tl;dr: A researcher achieved 60-80% attack success rates against Claude Code Opus 5's Auto Mode by hosting a website that redirects Claude to a ZIP archive containing a malicious `struct.py`; Claude refuses to run the included binary decoder but writes its own Python decoder and executes it inside the attacker's directory, triggering Python module shadowing when `base64` is imported, leading to RCE and C2 callback. Anthropic closed the report as "working as designed," contradicting their earlier marketing of a 0.00% prompt injection rate and reinforcing that Auto Mode is not a substitute for OS-level sandboxing. | |
HN Discussion:
| |