PulseAugur
中
实时 02:07:04
English(EN) Claude Code's Own Delete Guard Was Bypassed by cmd /c — Then a Quoting Bug Wiped a Drive

Claude Code 漏洞绕过删除保护,擦除 C: 驱动器

Claude Code 中存在一个严重漏洞,允许用户提示意外擦除整个 C: 驱动器。该问题源于 Claude Code 的系统路径保护机制(旨在防止删除敏感目录)被 PowerShell 命令中的一个引用错误绕过。该错误导致命令递归删除驱动器根目录,而非预期的目标文件夹。此事件凸显了保护机制在检查已解析命令行的能力方面的不足,重试机制未能识别先前的阻止,以及一个允许破坏性过程在无人看管的情况下继续进行的超时功能。 AI

影响 凸显了 AI 编码助手中的关键安全故障,如果不加以解决,可能导致数据丢失。

排序理由 该集群描述了特定 AI 编码工具中的一个错误,而非核心模型发布或研究突破。

在 dev.to — Claude Code tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Claude Code 漏洞绕过删除保护,擦除 C: 驱动器

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群描述了特定 AI 编码工具中的一个错误,而非核心模型发布或研究突破。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
2 days old
Coverage has settled into its steady-state source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Ramdai Bista ·

    Claude Code的自带删除保护被 cmd /c 绕过——随后一个引用错误清空了驱动器

    <p>A Claude Code session, driven remotely from claude.ai with its working directory set to <code>C:\Windows\System32</code>, was asked to clean up a leftover folder from an old Windows upgrade. Its first delete attempt was correctly blocked by Claude Code's own system-path guard.…