In August 2025, Rehberger showed the identical pattern against Claude Code, tracked as CVE-2025-55284.
Injected content drove the agent to encode API keys into DNS lookups through auto-approved network utilities, slipping past the normal command-approval prompt.
Learn More: AI Agent Tool Misuse & Exploitation: When an Agent's Own Tools Do the Damage
https://i.redd.it/o2ti99y9ecrh1.jpeg
Source: r/pwnhub · by /u/_clickfix_
