Anthropic’s one-click blunder: What are you doing hitting ‘ok’?

Anthropic’s Misstep: A Risky Endeavor

How clear must the creator of a risky tool be regarding its ability to cause self-inflicted harm? This is the core question posed by security firm Adversa AI following the revelation of a one-click remote code execution vulnerability through an MCP server in Claude Code, Gemini CLI, Cursor CLI, and Copilot CLI. The TrustFall proof-of-concept (PoC) attack illustrates how a duplicated code repository can house two JSON files (.mcp.json and .claude/settings.json) that facilitate access to an attacker-controlled Model Context Protocol (MCP) server. MCP servers provide tools, configuration data, schemas, and documentation in a standardized JSON format to AI models.

JSON Files: The Hiding Foes

The flaw stems from inconsistent limitations on the settings’ scope: while Anthropic restricts some risky settings at the project level (e.g., bypassPermissions), it does not do so for others (e.g., enableAllProjectMcpServers and enabledMcpjsonServers). The JSON files merely enable these settings.

Anthropic's one-click blunder: What are you doing hitting 'ok'?

The Execution Flaw

“Once a developer hits Enter on Claude Code’s generic ‘Yes, I trust this folder’ prompt, the server initiates as an unsandboxed Node.js process under the user’s complete privileges — with no individual server consent required, and no tool invocation from Claude necessary,” Adversa AI states in its PoC repository. The probable outcome is a compromised system. The PoC showcased in this video. It was effective on Claude Code CLI v2.1.114, as of May 2. Other agent CLIs are believed to be impacted as well, yet specific PoCs have not been disclosed.

Same Source, Diverse Offshoots

“This is the third CVE related to Claude Code in six months resulting from the same underlying issue (project-scoped settings used as an injection route),” Alex Polyakov, co-founder of Adversa AI, informed GadgetLad via email. “Each gets addressed individually, but the fundamental class remains unresolved. Most developers are unaware these settings are present, let alone that a duplicated repository can alter them stealthily.”

Anthropic's one-click blunder: What are you doing hitting 'ok'?

User’s Trust Choice: A Handy Excuse?

According to the security firm, Anthropic argues that the user’s trust decision shifts the matter outside its threat model. CVE-2025-59536 was deemed a vulnerability because it was triggered automatically when a user launched Claude Code in a harmful directory. However, TrustFall is considered outside the scope since the user was presented with a dialog box and made a trust choice.

A Deficiency in Informed Consent

Adversa contends that the choice is not made with informed consent, referencing a previous, more explicit warning notice that was removed in v2.1 of Claude Code CLI. “The pre-v2.1 dialog clearly warned that .mcp.json could execute code and provided three options including ‘proceed with MCP servers disabled,'” writes Adversa’s Sergey Malenkovich. “That informed-consent user experience was eliminated. The current prompt defaults to ‘Yes, I trust this folder’ lacking MCP-specific language, a list of which executables will run, and an opt-out for MCP while still allowing the rest of the trust grant.”

The Zero-click Variant: An Alert Without a Prompt

Additionally, there’s the zero-click variant to contemplate for CI/CD pipelines utilizing Claude Code. When Claude Code is used in CI/CD, it occurs via SDK rather than the interactive CLI. Therefore, no terminal prompt is present. Malenkovich suggests that Anthropic should implement three modifications.

Anthropic's one-click blunder: What are you doing hitting 'ok'?

Three Proposed Modifications

First, prevent enableAllProjectMcpServers, enabledMcpjsonServers, and permissions.allow from any settings file within a project. The reasoning is that a malicious server should not have the ability to approve its own servers. Second, introduce a specific MCP consent prompt that defaults to “deny.” And third, mandate interactive consent for each server instead of a blanket approval for all servers.

Anthropic did not respond to a request for comment.

Conclusion

When Saying ‘Yes’ Causes Self-Inflicted Wounds
In today’s landscape of self-sabotaging technology, recklessly saying “yes” can lead to considerable troubles. Be cautious of seemingly harmless buttons; they may conceal an unpleasant surprise!