Advisories
Published security advisories.
Vulnerability disclosures from our research. Each advisory includes full reproduction steps, impact analysis, and remediation guidance.
RDXS-2026-001 · 2026-03-07 · Claude Code 2.1.71
CriticalSupply-Chain Code Execution in Claude Code
A cloned repository can execute arbitrary shell commands on your machine the moment you run claude -p.
4 critical · 4 high · 8 total findings
RDXS-2026-002 · 2026-03-09 · Claude Code 2.1.71
CriticalRemote Bridge Trust Boundary Failures in Claude Code
A remote peer can bypass crash guards, trigger local OAuth fetches, and exhaust system memory before the operator approves any action.
2 critical · 1 high · 3 total findings
RDXS-2026-003 · 2026-03-10 · Wallet Extension 3.9.0
HighQR Login Session Hijacking in Crypto.com Wallet Extension
Unauthenticated QR session creation and missing creator/scanner binding allow an attacker to steal the approver's Bearer token and access account data.
0 critical · 2 high · 2 total findings
RDXS-2026-004 · 2026-03-10 · DoorDash Consumer App 15.221.7
CriticalOAuth Account Takeover in DoorDash Android App
Custom scheme redirect hijacking, no PKCE enforcement, and a hardcoded client secret enable full account takeover via authorization code interception.
1 critical · 1 high · 3 total findings
RDXS-2026-005 · 2026-03-11 · Claude Code 2.1.72
CriticalRemote Control Bridge Worker Chain in Claude Code
A malicious repository can steal the live session bearer from a Remote Control bridge worker, forge tool approvals, and persist machine-wide permission corruption that survives into future sessions.
6 critical · 1 high · 7 total findings
RDXS-2026-006 · 2026-03-11 · Claude Code 2.1.72
HighRemote Control Session Isolation Failures in Claude Code
Bridge bearer tokens are not session-scoped, plain OAuth can enumerate and control all active sessions, and organization UUID is not enforced — amplifying the blast radius of any stolen credential.
0 critical · 5 high · 5 total findings
RDXS-2026-007 · 2026-03-16 · gstack 0.4.4
MediumSecurity Review of gstack: Y Combinator CEO's Claude Code Toolkit
Two server-level security issues in the headless browser daemon, plus a design review of trust boundaries between human intent and autonomous AI agent action.
0 critical · 2 high · 2 total findings
RDXS-2026-008 · 2026-03-31 · Claude Code Source leak snapshot
HighLive Session Bearer Disclosure to MCP Servers in Claude Code
An attacker-controlled MCP server can receive the live session-ingress bearer in legacy bridge paths because Claude Code promotes product auth into generic MCP transport headers.
0 critical · 1 high · 1 total findings