# Claude Code RCE via Malicious .mcp.json in Pull Request Branches

> ImmersiveLabs researcher Kevin Breen disclosed that Claude Code (CLI and VS Code extension) automatically parses and launches Model Context Protocol servers defined in a repository's .mcp.json file at session startup, so a malicious .mcp.json smuggled into a pull request branch spawns an attacker-controlled local process under the developer's OS privileges the moment the branch is checked out and Claude Code is launched — with no per-command approval. Anthropic classifies the behavior as consistent with its workspace/folder trust model rather than a vulnerability requiring a fix.

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1929
- **ID:** TL-2026-1929
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-06 ImmersiveLabs (researcher Kevin Breen, Senior Director of Cyber Threat Research) published a proof-of-concept showing that Claude Code initializes locally-defined MCP servers from a project's .mcp.json during session startup before any user interaction, regardless of which git branch is currently checked out. Because Claude Code's folder-trust grant is established once per repository and is not re-evaluated on branch switches, an attacker who can land a pull request (or push to a branch a developer will check out) can add or modify a .mcp.json entry whose 'command'/'args' fields spawn an arbitrary local process — a reverse shell, a curl-pipe-to-shell staged payload, or an npx/Docker-wrapped malicious package — disguised as ordinary development tooling (e.g. a server named 'playwright'). The command executes with the developer's full OS-level privileges, with no sandboxing, no command allowlist, and no verification that the named MCP server is legitimate. Because SSH keys, cloud credentials, and shell environment variables are all reachable from that process, ImmersiveLabs frames the primary risk as silent, unattended compromise of developer workstations and downstream cloud/CI credentials.

Anthropic's response, quoted by ImmersiveLabs, is that 'when you trust a folder, that grant covers the repository's configuration...checking out...other branches does not re-trigger the trust prompt,' and the company characterized the reported behavior as 'working as designed' rather than a bug requiring a patch — positioning malicious branch/PR content as within scope of the existing folder-trust boundary rather than a new trust boundary of its own. No CVE has been assigned to this specific finding as of the 2026-08-07 GBHackers report, and no in-the-wild exploitation has been reported; this is PoC-stage vulnerability research.

This disclosure is the latest in a recurring pattern of Claude Code MCP/config trust-boundary findings during 2025-2026: Check Point Research's 'Caught in the Hook' work (CVE-2025-59536, an MCP consent bypass and SessionStart-hook RCE via .claude/settings.json, patched in Claude Code 1.0.111+; and CVE-2026-21852, ANTHROPIC_BASE_URL-based API key exfiltration, patched in 2.0.65+); a Tenable-credited flaw in the claude-code-action GitHub Action (CVE-2026-47751) where a PR-branch .mcp.json achieved arbitrary code execution in CI runners with access to workflow secrets (fixed in action v1.0.78); and a June 2026 Repello AI finding that Claude Code's MCP approvals are keyed to server *name* rather than the approved command content, so a name-preserving command swap in .mcp.json executes silently on next launch — which Anthropic also classified as 'working as designed.' Unlike those, the ImmersiveLabs finding targets the baseline, already-patched trust flow itself: even with prior fixes applied, an already-trusted folder's persisted trust extends across arbitrary future branch content by design, so no additional confirmation step exists between 'attacker lands a PR' and 'attacker's MCP command executes.'

## MITRE ATT&CK

- T1195.001 Compromise Software Dependencies and Development Tools
- T1059.004 Unix Shell
- T1059.007 JavaScript
- T1036.005 Match Legitimate Resource Name or Location
- T1552.001 Credentials In Files
- T1552.004 Private Keys
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1608.001 Upload Malware

## Sources

- [Claude Code RCE Flaw](https://gbhackers.com/claude-code-rce-flaw/)
- [Claude Code RCE Vulnerability: How a Malicious Pull Request Executes Code](https://www.immersivelabs.com/resources/blog/claude-code-rce-vulnerability-how-a-malicious-pull-request-executes-code)
- [Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files (CVE-2025-59536, CVE-2026-21852)](https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/)
- [Claude Code Action Runner Arbitrary Code Execution via Malicious MCP Server Configuration (TRA-2026-27, CVE-2026-47751)](https://www.tenable.com/security/research/tra-2026-27)
- [A Trusted Name Is Not a Trusted Command: MCP Approvals in Claude Code](https://repello.ai/blog/claude-code-mcp-name-keyed-trust)
- [Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration](https://thehackernews.com/2026/02/claude-code-flaws-allow-remote-code.html)
- [Claude Code Hacked to Achieve Full RCE and Hijacked Organization API keys](https://cybersecuritynews.com/claude-code-hacked/)
- [GHSA-ph6w-f82w-28w6: Claude Code MCP consent bypass / hooks RCE advisory](https://github.com/advisories/GHSA-ph6w-f82w-28w6)
- [Claude Code settings documentation (MCP servers, project trust)](https://code.claude.com/docs/en/settings)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1929
