STUPID-2026-0024
Claude Code MCP trust boundary failures allow workspace privilege escalation
Instruction given
Normal development tasks via Claude Code with MCP integrations
Expected behavior
MCP server interactions constrained by trust level; no privilege escalation possible
Actual behavior
Trust boundaries can be crossed through crafted MCP server configurations and tool descriptions; agent can be manipulated to perform out-of-scope privileged actions
Damage
Potential for workspace privilege escalation in Claude Code v2.1.63; Anthropic closed findings as Informative without CVE assignment
Classification
- Agent
- Claude Code
- Failure mode
- Security Vulnerability
- Root cause
- Other
- Domain
- Security
- Source
- Security Research
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.