Advisories

Published security advisories.

Vulnerability disclosures from our research. Each advisory includes full reproduction steps, impact analysis, and remediation guidance.

RDXS-2026-001 · 2026-03-07 · Claude Code 2.1.71

Critical

Supply-Chain Code Execution in Claude Code

A cloned repository can execute arbitrary shell commands on your machine the moment you run claude -p.

4 critical · 4 high · 8 total findings

RDXS-2026-002 · 2026-03-09 · Claude Code 2.1.71

Critical

Remote Bridge Trust Boundary Failures in Claude Code

A remote peer can bypass crash guards, trigger local OAuth fetches, and exhaust system memory before the operator approves any action.

2 critical · 1 high · 3 total findings

RDXS-2026-003 · 2026-03-10 · Wallet Extension 3.9.0

High

QR Login Session Hijacking in Crypto.com Wallet Extension

Unauthenticated QR session creation and missing creator/scanner binding allow an attacker to steal the approver's Bearer token and access account data.

0 critical · 2 high · 2 total findings

RDXS-2026-004 · 2026-03-10 · DoorDash Consumer App 15.221.7

Critical

OAuth Account Takeover in DoorDash Android App

Custom scheme redirect hijacking, no PKCE enforcement, and a hardcoded client secret enable full account takeover via authorization code interception.

1 critical · 1 high · 3 total findings

RDXS-2026-005 · 2026-03-11 · Claude Code 2.1.72

Critical

Remote Control Bridge Worker Chain in Claude Code

A malicious repository can steal the live session bearer from a Remote Control bridge worker, forge tool approvals, and persist machine-wide permission corruption that survives into future sessions.

6 critical · 1 high · 7 total findings

RDXS-2026-006 · 2026-03-11 · Claude Code 2.1.72

High

Remote Control Session Isolation Failures in Claude Code

Bridge bearer tokens are not session-scoped, plain OAuth can enumerate and control all active sessions, and organization UUID is not enforced — amplifying the blast radius of any stolen credential.

0 critical · 5 high · 5 total findings

RDXS-2026-007 · 2026-03-16 · gstack 0.4.4

Medium

Security Review of gstack: Y Combinator CEO's Claude Code Toolkit

Two server-level security issues in the headless browser daemon, plus a design review of trust boundaries between human intent and autonomous AI agent action.

0 critical · 2 high · 2 total findings

RDXS-2026-008 · 2026-03-31 · Claude Code Source leak snapshot

High

Live Session Bearer Disclosure to MCP Servers in Claude Code

An attacker-controlled MCP server can receive the live session-ingress bearer in legacy bridge paths because Claude Code promotes product auth into generic MCP transport headers.

0 critical · 1 high · 1 total findings