Anthropic Claude Code security update

Two separate disclosures show AI coding assistants and local developer servers can be abused: Claude Code's default-trust agent behavior enables repo-based RCE, while Cline Kanban v0.1.59 exposes local WebSocket endpoints to cross-origin attacks.

Part of the PlainSec briefing for 2026-05-07

Editions

Sources