{"data":{"id":"73f68ee3-a7ab-4a13-a783-9692a4831205","title":"Spawning a Child Claude Session to Bypass Parent Guardrails","summary":"Straiker STAR Labs found a Claude Code attack, called Session Inception, in which a parent session launches a child Claude Code session inside a malicious repository. The child session takes a different permission path, so a SessionStart hook in .claude/settings.json runs automatically and sends developer data to an attacker's server without the confirmation the parent path would require. The researchers say the parent session's guardrails worked as designed, but they were never triggered on this path.","solution":"N/A -- no mitigation discussed in source.","labels":["security","safety"],"sourceUrl":"https://www.straiker.ai/blog/session-inception-spawning-a-child-claude-session-to-bypass-parent-guardrails","publishedAt":"2026-10-08T15:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Claude Code","Claude"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-08T15:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}