Breaking Claude Code Opus 5 Auto Mode
Summary
Researchers found a way to hijack Claude Code Opus 5 in Auto Mode, a feature that automatically executes code without asking the user for approval, achieving a 60-80% attack success rate through a simple website summary request. This contradicts Anthropic's own safety evaluation, which reported a 0% success rate for prompt injection attacks (tricking an AI by hiding malicious instructions in normal-looking input) against this mode. Auto Mode became the default setting for Claude Code in mid-August, making this vulnerability potentially affect many users.
Classification
Affected Vendors
Related Issues
Original source: https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
First tracked: August 27, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 92%