MediumNewsLLM-specific
Spawning a Child Claude Session to Bypass Parent Guardrails
- Published
- Record updated
Summary
Straiker STAR Labs found a Claude Code attack, called Session Inception, in which a parent session launches a child Claude Code session inside a malicious repository. The child session takes a different permission path, so a SessionStart hook in .claude/settings.json runs automatically and sends developer data to an attacker's server without the confirmation the parent path would require. The researchers say the parent session's guardrails worked as designed, but they were never triggered on this path.
Related items
- InfoRogue Anthropic AI agent gave police fake tip in unsolved murder caseSame vendor · BBC Technology
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSame vendor · The Hacker News
- InfoQuoting The New York TimesSame vendor · Simon Willison's Weblog
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer