Home / Incidents / STUPID-2026-0024
STUPID-2026-00247.5highClaude CodeVerified

Claude Code MCP trust boundary failures allow workspace privilege escalation

7.5/10
Severity
Security Vulnerability
Failure Mode
Reproducible
Yes
Date
March 22, 2026

Expected Behavior

MCP server interactions constrained by trust level; no privilege escalation possible

What Actually Happened

Trust boundaries can be crossed through crafted MCP server configurations and tool descriptions; agent can be manipulated to perform out-of-scope privileged actions

Damage Assessment

Potential for workspace privilege escalation in Claude Code v2.1.63; Anthropic closed findings as Informative without CVE assignment

Full Report

Security researcher Jashid Sany documented three systemic trust boundary failures in Claude Code v2.1.63 related to the Model Context Protocol (MCP): (1) weak MCP server configuration validation allowing untrusted servers to register with elevated trust, (2) insufficient tool confirmation prompts that can be bypassed by crafted tool descriptions, and (3) workspace trust escalation vulnerabilities where agents processing potentially malicious input can be manipulated to perform out-of-scope actions. All findings were submitted to Anthropic via HackerOne and closed as 'Informative'. The core failure: human-designed trust models break when autonomous agents process potentially adversarial input.

Incident Metadata

Agent
Claude Code
Failure Mode
Security Vulnerability
Root Cause
Other
Task Type
agentic_operations
Domain
security
Source
security_research
View Source