Cortex MCP Server Directory Trust Leads to Arbitrary Code Execution via CLAUDE_PROJECT_DIR Spoofing
highAgentCode ExecutionThe Cortex MCP server incorrectly trusts the CLAUDE_PROJECT_DIR environment variable to identify a legitimate Cortex source checkout, using only two file-presence checks as validation. An attacker who convinces a victim to open a malicious repository as their active project in Claude Code can plant these marker files and cause Cortex's open_visualization tool to execute an arbitrary attacker-controlled Python script with the victim's local user privileges.
Updated Aug 14, 2026