Posted by Armor1AI 1 day ago
You can still see the exclusion on HackerOne: https://hackerone.com/anthropic-vdp/policy_scopes
Out of Scope:
Abusing intended functionality of Claude CLI
Using aliased commands, symlinks or other environment-specific settings to bypass permission prompts
Local storage of Claude Code credentials, configuration and logs
Symlinks have been very important to manage skills from disparate sources and managing multiple CLIs.Codex did not originally support symlink'd skills but added it in response to user requests on Jan 9th.
Anthropic response to 1-click pwn: Shouldn't have clicked 'ok': https://news.ycombinator.com/item?id=48057836
This makes me think a bit more about this CVE more too.
Anthropic lately has been really trying to burn any/every good will that they have it seems. Also a bit ironical about how the most dangerous model (Mythos) which can find CVE in other projects wasn't able to find this CVE within the claude-code project itself.
It's the first thing people will point mythos at.
The shoemaker's children go barefoot and all...