Y
Hacker News
new
|
ask
|
show
|
jobs
I reproduced a Claude Code RCE. The bug pattern is everywhere
(
vechron.com
)
7 points
by
GeorgeWoff25
30 days ago
2 comments
ashishgupta2200
30 days ago
This is a good argument for treating ai agent products like you’d treat a browser or PDF reader, assume untrusted input all the way through and sandbox ruthlessly, instead of sprinkling a couple of string checks and calling it a day
link
GeorgeWoff25
30 days ago
Joernchen found it. I reproduced it and checked if Cursor and Continue.dev have the same startsWith parsing issue. They do.
link