Anthropic's Claude Code vulnerable to prompt injection attacks
Story essentials
Johann Rehberger, Anthropic
Global
August 2026
Show 1 more
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policy- Earlier version 18/29/2026, 2:40:55 AM
Security researcher Johann Rehberger demonstrated that Claude Code in Auto Mode can be tricked into executing malicious code. The attack involves manipulating the model to use unintended tools and shadowing Python modules to run unauthorized payloads. Anthropic maintains that the model's behavior is working as designed, emphasizing that Auto Mode is not a security guarantee.
Read next
Prioritized by shared people, places, and events.
Anthropic CEO Dario Amodei addresses AI backlash and regulation
Anthropic CEO Dario Amodei defended his messaging on AI risks, stating it is balanced with benefits. Amodei attributed the public's negative view of AI to a broader 'crisis of trust' in institutions. He argued that regulation should constrain frontier AI companies while advantaging smaller competitors.