Claude Code Vulnerabilities: Arbitrary Code Execution
With more than 10 million weekly downloads, Anthropic’s Claude Code CLI has become an integral part of the modern development ecosystem. The adoption of Model Context Protocol (MCP) gives this AI agent expanded capabilities while also creating new attack vectors across enterprise infrastructure.
Researchers at Sonar identified two critical vulnerabilities that allowed cybercriminals to execute arbitrary code on a user’s machine before the user approved the tool’s access to the workspace. While current discussions are largely focused on LLM-specific risks such as prompt injection, foundational security flaws in development environments and configurations remain a top defensive priority.

