A researcher hijacked Claude Code by asking it to summarise a web page
The Next Web
Read full postSecurity researcher Johann Rehberger demonstrated a vulnerability in Claude Code's Auto Mode where the AI agent can be tricked into executing attacker-supplied code by manipulating web page responses and local Python module loading. This exploit leverages Claude's fallback to Bash commands and Python's module shadowing to run arbitrary code, including launching additional Claude instances with tool access.

- Breaking Claude Code Opus 5 Auto Mode· Simon Willison's Weblog



