STUPID-2026-0024

Claude Code MCP trust boundary failures allow workspace privilege escalation

7.5high
March 22, 2026VerifiedReproducible
  1. Instruction given

    Normal development tasks via Claude Code with MCP integrations

  2. Expected behavior

    MCP server interactions constrained by trust level; no privilege escalation possible

  3. Actual behavior

    Trust boundaries can be crossed through crafted MCP server configurations and tool descriptions; agent can be manipulated to perform out-of-scope privileged actions

  4. Damage

    Potential for workspace privilege escalation in Claude Code v2.1.63; Anthropic closed findings as Informative without CVE assignment

Security researcher Jashid Sany documented three systemic trust boundary failures in Claude Code v2.1.63 related to the Model Context Protocol (MCP): (1) weak MCP server configuration validation allowing untrusted servers to register with elevated trust, (2) insufficient tool confirmation prompts that can be bypassed by crafted tool descriptions, and (3) workspace trust escalation vulnerabilities where agents processing potentially malicious input can be manipulated to perform out-of-scope actions. All findings were submitted to Anthropic via HackerOne and closed as 'Informative'. The core failure: human-designed trust models break when autonomous agents process potentially adversarial input.

Classification

Root cause
Other
Domain
Security

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.