Threat reportVulnerabilityTL-2026-1929

Claude Code RCE via Malicious .mcp.json in Pull Request Branches

highACTIVE

Claude Code RCE via Malicious .mcp.json in Pull Request (TL-2026-1929) is a high-severity software vulnerability, first published 2026-08-07. It has no confirmed attribution, affects Anthropic Claude Code, maps to 10 MITRE ATT&CK techniques (T1005, T1036.005, T1059.004), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-1929

Threat ID
TL-2026-1929
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in Claude Code RCE via Malicious .mcp.json in Pull Request

Malware and tooling: Claude Code CLI, Claude Code VS Code extension, playwright

How Claude Code RCE via Malicious .mcp.json in Pull Request works

ImmersiveLabs researcher Kevin Breen disclosed that Claude Code (CLI and VS Code extension) automatically parses and launches Model Context Protocol servers defined in a repository's .mcp.json file at session startup, so a malicious .mcp.json smuggled into a pull request branch spawns an attacker-controlled local process under the developer's OS privileges the moment the branch is checked out and Claude Code is launched — with no per-command approval. Anthropic classifies the behavior as consistent with its workspace/folder trust model rather than a vulnerability requiring a fix.

On 2026-08-06 ImmersiveLabs (researcher Kevin Breen, Senior Director of Cyber Threat Research) published a proof-of-concept showing that Claude Code initializes locally-defined MCP servers from a project's .mcp.json during session startup before any user interaction, regardless of which git branch is currently checked out. Because Claude Code's folder-trust grant is established once per repository and is not re-evaluated on branch switches, an attacker who can land a pull request (or push to a branch a developer will check out) can add or modify a .mcp.json entry whose 'command'/'args' fields spawn an arbitrary local process — a reverse shell, a curl-pipe-to-shell staged payload, or an npx/Docker-wrapped malicious package — disguised as ordinary development tooling (e.g. a server named 'playwright'). The command executes with the developer's full OS-level privileges, with no sandboxing, no command allowlist, and no verification that the named MCP server is legitimate. Because SSH keys, cloud credentials, and shell environment variables are all reachable from that process, ImmersiveLabs frames the primary risk as silent, unattended compromise of developer workstations and downstream cloud/CI credentials.

Anthropic's response, quoted by ImmersiveLabs, is that 'when you trust a folder, that grant covers the repository's configuration...checking out...other branches does not re-trigger the trust prompt,' and the company characterized the reported behavior as 'working as designed' rather than a bug requiring a patch — positioning malicious branch/PR content as within scope of the existing folder-trust boundary rather than a new trust boundary of its own. No CVE has been assigned to this specific finding as of the 2026-08-07 GBHackers report, and no in-the-wild exploitation has been reported; this is PoC-stage vulnerability research.

This disclosure is the latest in a recurring pattern of Claude Code MCP/config trust-boundary findings during 2025-2026: Check Point Research's 'Caught in the Hook' work (CVE-2025-59536, an MCP consent bypass and SessionStart-hook RCE via .claude/settings.json, patched in Claude Code 1.0.111+; and CVE-2026-21852, ANTHROPIC_BASE_URL-based API key exfiltration, patched in 2.0.65+); a Tenable-credited flaw in the claude-code-action GitHub Action (CVE-2026-47751) where a PR-branch .mcp.json achieved arbitrary code execution in CI runners with access to workflow secrets (fixed in action v1.0.78); and a June 2026 Repello AI finding that Claude Code's MCP approvals are keyed to server *name* rather than the approved command content, so a name-preserving command swap in .mcp.json executes silently on next launch — which Anthropic also classified as 'working as designed.' Unlike those, the ImmersiveLabs finding targets the baseline, already-patched trust flow itself: even with prior fixes applied, an already-trusted folder's persisted trust extends across arbitrary future branch content by design, so no additional confirmation step exists between 'attacker lands a PR' and 'attacker's MCP command executes.'

MITRE ATT&CK techniques used in TL-2026-1929

Collection

T1005 Data from Local System

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Execution

T1059.004 Unix Shell; T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols; T1095 Non-Application Layer Protocol

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools

Credential Access

T1552.001 Credentials In Files; T1552.004 Private Keys

Resource Development

T1608.001 Upload Malware

Affected products and versions in Claude Code RCE via Malicious .mcp.json in Pull Request

  • Anthropic — Claude Code
    Vulnerable versions: All versions implementing the current project-scoped MCP/.mcp.json trust model as of the 2026-08-06 disclosure
  • Anthropic — Claude Code VS Code extension
    Vulnerable versions: All versions sharing the CLI's MCP initialization and folder-trust behavior as of the 2026-08-06 disclosure

Remediation for Claude Code RCE via Malicious .mcp.json in Pull Request

Immediate actions

  • Treat .mcp.json and .claude/ (settings.json, hooks) as executable code, not passive configuration, in code review
  • Review the exact command/args/env fields of any .mcp.json change before checking out a branch or merging a PR that touches it
  • Apply heightened scrutiny to pull requests from external or first-time contributors that add or modify .mcp.json or .claude/settings.json
  • Run `claude mcp reset-project-choices` to clear stale project-level MCP approvals rather than relying on standing 'allow all future' grants

Workarounds

  • Do not launch Claude Code (CLI or VS Code extension) inside a working directory immediately after checking out an unreviewed or untrusted branch/PR
  • Isolate untrusted branch checkouts in disposable dev containers or VMs when Claude Code will be run against them

Longer-term hardening

  • Avoid selecting the 'Use this and all future MCP servers in this project' standing-grant option; approve MCP servers individually where possible
  • Add CI/CD or pre-commit gating that flags any diff touching .mcp.json, .claude/settings.json, or other agent-read configuration files for mandatory human review
  • Track Anthropic's guidance and any future hardening of MCP approval binding (name-keyed vs. command-content-keyed trust)

Weaknesses (CWE) in Claude Code RCE via Malicious .mcp.json in Pull Request

CWE-862, CWE-829

Timeline of Claude Code RCE via Malicious .mcp.json in Pull Request

  • Check Point Research reports the first related Claude Code trust-boundary flaw to Anthropic: SessionStart hooks in .claude/settings.json executing arbitrary commands without user confirmation.
  • GitHub Security Advisory GHSA-ph6w-f82w-28w6 published, covering the MCP consent-bypass / hooks RCE issue later tracked as CVE-2025-59536.
  • CVE-2025-59536 (Claude Code MCP consent bypass via enableAllProjectMcpServers) formally published; fixed in Claude Code 1.0.111+.
  • CVE-2026-21852 (API key exfiltration via malicious ANTHROPIC_BASE_URL override) published; fixed in Claude Code 2.0.65+.
  • Rémy Marot reports the claude-code-action GitHub Action MCP configuration RCE (later CVE-2026-47751) to Anthropic; PR head-branch checkout plus default enableAllProjectMcpServers allows CI-runner code execution with workflow secrets.
  • Check Point Research publicly discloses the 'Caught in the Hook' findings (CVE-2025-59536, CVE-2026-21852), amplified by The Hacker News and other outlets.
  • claude-code-action v1.0.78 released fixing CVE-2026-47751; Tenable confirms remediation on 2026-03-25.
  • Repello AI reports the MCP name-keyed trust flaw to Anthropic (approvals bound to server name, not command content); Anthropic responds the same day classifying it as 'working as designed.'
  • ImmersiveLabs (Kevin Breen) publishes the PR-branch .mcp.json RCE research: a malicious .mcp.json checked out via a pull request branch executes local commands under developer privileges on Claude Code launch, with no additional approval since the repository folder is already trusted.
  • GBHackers reports on the ImmersiveLabs disclosure; Anthropic reiterates that trusting a folder covers its configuration across all subsequently checked-out branches, declining to treat this as a new vulnerability requiring a code change.

Sources cited for Claude Code RCE via Malicious .mcp.json in Pull Request

Detection coverage for TL-2026-1929

As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1929 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats