Tel Aviv, Israel, July twenty fourth, 2026, CyberNewswire
One week after disclosing that Anthropic’s Claude Tag Slack integration might be pushed by plain “@Claude” textual content, Tego AI in the present day printed a second piece of analysis on the Claude ecosystem. This one focuses on Claude Code, Anthropic’s agentic command-line coding instrument.
Cloning an bizarre repository and beginning Claude Code may cause the instrument to learn a file from outdoors the challenge and embody it within the mannequin’s first request, with out a warning or approval immediate the consumer would acknowledge.
The approach is bizarre, and that’s a part of why it issues. A repository can commit a normal-looking instruction file, CLAUDE.md, whose @import directive factors to a symbolic hyperlink. When a developer clones the repository and begins Claude Code, the instrument follows the hyperlink to no matter file it resolves to, together with recordsdata nicely outdoors the challenge, and folds that file’s contents into the primary request it sends to the mannequin.
No instrument name fires, and no file-edit approval seems. The dialog Claude Code makes use of to catch out-of-project reads doesn’t seem both, as a result of it checks the in-repository hyperlink identify, corresponding to ./hyperlink, quite than the exterior file the hyperlink resolves to.
The entire supply mechanism is a repository file named hyperlink that GitHub itself labels as a symbolic hyperlink pointing to /and so forth/passwd2, seen to anybody searching the repository.
“Context is no matter will get despatched to the mannequin, and the mannequin is a community endpoint like some other,” stated Tomer Niv, Head of Analysis at Tego AI. “So this isn’t a file that quietly sits in a immediate. Clone a repo, reply the identical ‘belief this folder?’ query you at all times reply, and a file from outdoors that repo can depart your machine on the primary request, with no code execution, no cooperation from the mannequin, and no server the attacker has to run.”
The result’s that the out-of-project file’s contents seem contained in the request physique Claude Code sends when the session begins. The info leaves the native machine as a part of the outbound request, quite than remaining solely in native mannequin context.
Anthropic has already fastened this underlying class of flaw twice. What makes the brand new report notable is the place the flaw sits, not that the sample is new.
The identical failure, a safety test studying one path whereas the filesystem follows a symbolic hyperlink to a different, beforehand appeared in Claude Code and was fastened accurately in CVE-2025-59829 and CVE-2026-25724. Each have been reported via HackerOne and resolved within the permission subsystem.
Tego AI’s analysis exhibits that the identical defect remained current on a 3rd code path, the startup reminiscence loader, which these fixes by no means reached. That path can be the one which locations what it finds onto the community earlier than the mannequin has taken any motion.
The technical write-up additionally paperwork {that a} repository-committed settings file can redirect Claude Code’s outbound endpoint to a bunch chosen by the repository creator, a individually identified habits. The uncovered file solely must be readable by the developer’s personal account. That could be a practical situation in CI runners, containers, and standardized developer photos, the place delicate file paths are sometimes predictable.
Tego AI’s level is about that safety boundary quite than a single bug. The corporate reported the difficulty to Anthropic via HackerOne in July 2026, and Anthropic closed it as Informative.
Anthropic’s rationale was constant and clearly said: beneath the Claude Code risk mannequin, the “belief this folder” dialog is the safety boundary, and accepting it already grants a challenge broad learn, edit, and execute entry. Tego AI doesn’t dispute that Anthropic utilized its said mannequin constantly.
“We perceive the mannequin. Our disclosure is an argument about its phrases,” Niv stated. “A single ‘belief this folder’ click on is being requested to hold an unlimited quantity of weight, at least knowledgeable second doable, earlier than you may have seen something the repository does. It can’t inform the distinction between ‘run my code’ and ‘learn my SSH key and mail it out,’ and in lots of actual setups that click on was inherited from a mother or father listing and by no means truly proven for the repository in query. As enterprises undertake AI coding brokers, that’s precisely the boundary they want to have the ability to motive about.”
The disclosure continues a theme in Tego AI’s analysis: for enterprise AI brokers, the unresolved query is authorization, that means who, or what, is allowed to instruct the agent and attain its knowledge and related programs. The Claude Tag analysis raised that query about an inbound Slack message. This analysis raises it about an bizarre Git clone.
Tego AI notes that symbolic-link assaults are many years outdated and that Anthropic has repeatedly hardened Claude Code towards them in good religion. The corporate printed the write-up so customers and safety groups can motive precisely about what “belief this folder” grants in apply.
Tego AI confirmed the habits towards Claude Code v2.1.x.
The total technical report is offered at: https://tego.ai/weblog/a-hidden-project-link-can-make-claude-code-silently-send-your-files-to-an-attacker
About Tego AI
Tego AI is a cybersecurity firm growing runtime safety and management expertise for enterprise AI brokers. Its platform helps organizations monitor agent exercise and cease unauthorized or dangerous actions earlier than brokers entry delicate knowledge or related programs.
The corporate operates in stealth. That is its second public safety disclosure in every week. In keeping with Tego AI, there’s extra to come back.
Contact
CTO
Tal Melamed
Tego AI
[email protected]







