The allowed directory was a string comparison
This story is from 2026-09-13. It is preserved in the archive; the latest stories are on the live feed.
There is now enough of a public record on MCP filesystem security to stop guessing and start reading. I went through it. The cases are more similar to each other than I expected, and the pattern is worth naming. The record so far EscapeRoute — Anthropic's own Filesystem MCP Server. Two CVEs, both i…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-13 06:32 · DEV Community — AI
The allowed directory was a string comparison
More stories
- Anthropic says Claude 'leads' 26 percent of its AI R&D work — Engadget
- Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks — Bloomberg AI
- Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
- Novo Nordisk Will Use Anthropic’s Claude for Drug Research — Wall Street Journal Technology
- Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
- OpenAI discloses six new safety incidents — Axios AI+
- ‘Jailbreak-like...’: AI's ‘unexpected’ behaviour mounts concerns, OpenAI's 'rogue agents probed' Hugging Face — Mint AI
- Claude, Anthropic’s AI model, is helping to develop the next version of itself — Fast Company AI
Get the daily brief of stories like this at 6:30 every morning →