Hacker Newsnew | past | comments | ask | show | jobs | submit | 0dd's commentslogin

Author here. Happy to answer questions


A full technical analysis with PoC video:

https://oddguan.com/blog/anthropic-sandbox-cve-2025-66479/

1. Docs promised empty allowedDomains = no network access but Actually disabled all restrictions (macOS + Linux) 2. No CVE for Claude Code, Compare: React & Next.js both got CVEs for RSC issue


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: