https://github.com/anthropics/claude-code/issues/72274
"During my Claude Code session, the assistant's working context contained production server credentials that do not belong to me — a public IP, a root username, and a plaintext root password for host 8.211.46.34. These credentials were presented as if they were mine. Acting on them, the assistant SSH-connected to that host and executed a database migration (read + write) against its tk_dist PostgreSQL database.
I have never owned, provisioned, or had any relationship with 8.211.46.34. My only server is 59.110.139.37. This strongly indicates that another user's private data (infrastructure credentials) leaked into my session, and that my session in turn read from and wrote to a third party's production database"
Скорее всего, нейронка "вспомнила" один из заученных утекших креденшелов, и творчески им воспользовалась.
UPD: и еще https://github.com/anthropics/claude-code/issues/74066
(предложка)
Post #11258
963
Forwarded from commit -m "better"
GitHub [Bug] Cross-session credential leakage: production database modified on unauthorized host · Issue #72274 · anthropics/claude-code Bug Description Here is a clear, submittable English bug report. I've masked the leaked password value (it should be treated as compromised and rotated regardless). BUG REPORT — Cross-Session D...- 🤣 17
- 🌚 5
- ❤ 2
- 🤯 1