anthropic is vulnerable to Improper Authorization
61
Medium Risk
The beta Sessions SessionToolRunner dispatched every agent.tool_use and agent.custom_tool_use event immediately on arrival and ignored the server-supplied evaluated_permission verdict. A tool configured with an ask or always_ask permission policy therefore executed before, or entirely without, the user confirmation the policy required. The fix routes tool-call events through a confirmation gate that holds ask-gated calls until a matching user.tool_confirmation allow verdict arrives, never runs denied calls, and fails closed on unrecognized permissions or verdicts. This restores the human-in-the-loop approval the permission policy is meant to enforce.
You are affected if you are using a version that falls within the vulnerable range and you run the beta Sessions SessionToolRunner with tools configured under an ask or always_ask permission policy.
anthropic is vulnerable to Improper Authorization in versions 0.103.0 - 0.116.0.
Upgrade the anthropic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant