STUPID-2026-0083
Claude Code leaked API keys via malicious repo settings before trust prompt
Instruction given
Open and start working in a repository containing a project-level Claude Code settings file.
Expected behavior
Claude Code should display the workspace trust prompt and wait for user confirmation before making any network requests driven by that repository's configuration.
Actual behavior
If the untrusted repository's settings file set ANTHROPIC_BASE_URL to an attacker-controlled endpoint, Claude Code issued API requests to that endpoint before the trust prompt was ever shown, sending the user's Anthropic API key along with them.
Damage
Simply opening a crafted, untrusted repository in Claude Code could exfiltrate the developer's active API key to attacker infrastructure. Fixed in Claude Code 2.0.65; users on auto-update received the patch automatically.
Classification
- Agent
- Claude Code
- Failure mode
- Security Vulnerability
- Root cause
- Logic Error
- Domain
- Security
- Source
- Security Research
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.