Claude Code Auto Mode를 우회하여 원격 코드 실행 성공.
공격자는 간접 프롬프트 인젝션을 이용해 웹사이트를 요약하게 하여 공격자 서버에 연결하는 데 성공했습니다. 소규모 표본에서 공격 성공률은 60~80%에 달했습니다. 또한, WebFetch가 실패한 상황에서 Opus 5는 curl과 셸을 사용하여 Python 디렉토리에 직접 접근했습니다.
Attackers bypass Claude Code Auto Mode for remote code execution.
Attackers successfully connected to their servers using indirect prompt injection that summarizes a website. The success rate of attacks was between 60-80% in a small sample. Additionally, in the failure of WebFetch, Opus 5 autonomously utilized curl and shell to directly access a Python directory.