From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG
1 September 2026 at 14:39
Abusing the trust boundary in Claude Code for RCE. Trust is never broken and that opens up a few avenues for abuse. Simply opening claude code on a PR can be enough to silently trigger attacker payloads.
Using Claude Code to find and weaponise an XSS in MeshCentral using a rogue client, resulting in RCE.