Hey, the Open Source model just proved its advantages :)
Claude Code bypasses safety rule if given too many commands
Claude Code will ignore its deny rules, used to block risky actions, if burdened with a sufficiently long chain of subcommands. This vuln leaves the bot open to prompt injection attacks. Adversa, a security firm based in Tel Aviv, Israel, spotted the issue following the leak of Claude Code's source. Claude Code implements …
COMMENTS
-
Wednesday 1st April 2026 23:36 GMT that one in the corner
A parser referred to as "tree-sitter"
Ah, isn't that a parser that has been written using tree-sitter, rather than a parser that is *called* tree-sitter?
So do we know the name of the parser? Or just that the name of the song is called 'Haddocks' Eyes'."
-
Thursday 2nd April 2026 13:30 GMT breakfast
If you're interested in what the Claude Code leaks reveal...
It's worth checking out this mastodon thread from @Jonny on Nuromatch.social in which he tries to unravel the spaghetti. It is hilarious and horrifying by turns.