Monday, September 7, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Morning Edition Free of Charge
TODAY'S LEAD STORY

"The problem wasn't with the model, but with the harness"—a single GitHub issue that simultaneously affected Claude Code, Gemini CLI, and Codex.

This article explains the vulnerability disclosed by Novee Security at Black Hat USA 2026 (and revisited in September) that allows a GitHub account with zero privileges to access the cİ execution environments of Claude Code, Gemini CLI, and OpenAI Codex. It covers CVE-2026-54316, which uses the download count of Hugging Face as a data exfiltration route, CVE-2026-12537, a Gemini CLI vulnerability with a perfect CVSS score of 10.0, the differences in responses such as OpenAI's claim that it was "according to specifications" and the fact that it remained unpatched, and the spread of the same pattern to over 100 public repositories, all from the perspective of distinguishing between "model judgment" and "harness design."

"The problem wasn't with the model, but with the harness"—a single GitHub issue that simultaneously affected Claude Code, Gemini CLI, and Codex.
(Photo: illustrative)

"The Harness Was the Vulnerability, Not the Model"—A Single GitHub Issue Simultaneously Vulnerable to Claude Code, Gemini CLI, and Codex

A research finding, announced at Black Hat USA 2026 and gaining renewed attention in September, reveals a vulnerability discovered by Elad Meged, a researcher at security firm Novee Security. This vulnerability allows an account with no repository privileges to access sensitive information within the CI (Continuous Integration) execution environments of Anthropic, Google, and OpenAI's AI coding agents simply by posting a single GitHub issue. As an engineer, I want to carefully examine this research finding, centered on the concept of "harness."

Separating "Model Decisions" from "Harness Design"

The most important concept in this research is the term "harness." Meged explains it as "the code between the model and the real world." An AI coding agent is not simply a system where a language model returns a response; it only functions as a practical agent when various "pipes" such as permission management, tool invocation paths, sandbox (isolation environment) control, shared workspaces, and execution environments are combined around the model.

The three vulnerabilities discovered this time all existed in this "pipe" section. In other words, the AI ​​model itself did not make a malicious decision; rather, there was an oversight in the design surrounding the model.

"Inconsistent String Interpretation" that Permeated Claude Code

The problem found in Anthropic's "Claude Code" (CVE-2026-54316) stemmed from a subtle discrepancy where the same string was interpreted differently during command validation and actual execution. Claude Code's command validation function removes text enclosed in single quotes before executing 23 check items. While this is correct behavior for bash (the shell), the attack code embedded in the value of git's `--receive-pack` flag slipped through this removal process and was interpreted directly by git at runtime.

Even more troublesome is the "information exfiltration route" used to exploit this vulnerability. Researchers exploited a feature of Hugging Face, for which Claude Code already had authorized access, using the publicly available "download count" counter as a hidden communication channel. This was an extremely sophisticated method, encoding the API key character by character in the form of increases and decreases in the download count before sending it.

Gemini CLI's "Perfect CVSS Score" Severity

The vulnerability found in Google's Gemini CLI (CVE-2026-12537) was even more serious. The "automatic workspace trust" mechanism in headless mode (automatic execution without screen display) combined with a design flaw where the allow list was "checked during registration but not enforced during execution" allowed the parent process's environment variables to be read through the Linux `/proc` filesystem. This vulnerability was given a perfect CVSS score of 10.0.

OpenAI Codex maintains "sandbox is working as specified"

OpenAI's response differed from the other two companies. In response to the researchers' report, OpenAI maintained that its sandbox "worked exactly as documented," and stated that no patch or CVE number was assigned to the Codex discovery in the product version. This incident highlights that the criteria for evaluating the severity of vulnerabilities can vary from company to company.

The same pattern spreading across "over 100 public repositories"

Another noteworthy aspect of this investigation is the Cloud Security Alliance's analysis. Similar configuration issues have been found in over 100 public repositories. Many of these repositories reportedly copied the official reference implementations (reference workflows) provided by Anthropic, Google, and OpenAI.

In other words, the vulnerability discovered was not limited to a single repository, but was inherent in the vendor's default settings themselves, and the same risk was spread to countless projects that adopted those settings without modification. The underlying structural problem (string-level validation differing from actual shell and file system interpretation) is said to be common to similar vulnerabilities reported in the past, such as "Clinejection," "GhostCommit," and "GuardFall."

Responses from Each Company and the Fact That It Has Already Been Fixed

Fortunately, at the time of the Black Hat announcement, the vulnerabilities in both Google and Anthropic's systems had already been patched. The Gemini CLI was fixed in version 0.39.1, and Claude Code in version 2.1.163. Google evaluated this report through its vulnerability bounty program and acknowledged the work of Meged and Dan Rishichikin of Pillar Security. Anthropic also released a patch and updated its security guidance, adding a warning about the possibility of content sanitizers being bypassed.

What Engineers Should Consider

The lesson from these findings is clear. When evaluating the security of an AI coding agent, it's insufficient to only look at the model's ability to reject dangerous instructions. Rather, the vulnerabilities that are often overlooked lie in the surrounding implementation (harness)—how the agent actually invokes tools, manages permissions, and configures the sandbox.

For engineers who have integrated or are planning to integrate AI coding agents into their CI/CD pipelines, this incident serves as a concrete call to action: "Re-audit all automated workflows that can be triggered externally." Instead of unconditionally trusting the default settings provided by the vendor, it's worth taking the time to manually verify what permissions and access scope they actually have in your environment.

サイバーセキュリティAIエージェント脆弱性Claude CodeGemini

A task that was supposed to take "several years" was completed in 11 days—a record of how AI, after numerous failures, finally proved Fermat's Last Theorem.

In September, Anthropic announced that Claude had completed the first complete computer-verified proof of Fermat's Last Theorem using Lean 4, working almost autonomously for 11 days. This article summarizes the scale of the project—13 million lines of code, 30,300 theorems, and approximately 6 billion output tokens—from its initial failures due to redundant work caused by local context accumulation, to the turning point where the collaborative platform Prove2Me by Tianyi Peng and others at Columbia University brought stable operation, to Kevin Buzzard's verification and evaluation, the differences in nature from OpenAI Astra's mathematical discovery, and the important reservations regarding reliance on external academic infrastructure, all from a researcher's perspective.

A Task That Was Expected to Take Years Completed in 11 Days—The Story of an AI That Completely Proven Fermat's Last Theorem Through Repeated Failures

In September, Anthropic announced that it had completed the first complete, computer-verified proof of Fermat's Last Theorem using Lean (a formal language that allows computers to verify mathematical proofs line by line). This was the result of Claude working almost autonomously for 11 days. As a journalist with a background in AI research, I want to carefully examine the technical details of this achievement and what happened during the process.

A Precise Understanding: It Was a "Translation," Not a "Proof"

First, there's an important distinction to grasp. What Claude did was not "discover" Fermat's Last Theorem, a mathematical fact already proven by Andrew Wiles in 1995. Rather, the proof by Wiles (and subsequent revisions by other researchers) was "translated" into a formal language called Lean 4, making it possible for a computer to mechanically verify each logical step.

This process (called auto-formalization) is not about reconfirming the correctness of the proof itself, but rather a qualitative contribution that "allows proof-assistance systems to verify all logical dependencies, rather than relying solely on human mathematical review." Mathematicians initially estimated this formalization process would take several years.

The sheer scale of the achievement: 13 million lines and 29,500 theorems

The numbers illustrating the scale of this achievement are astonishing. In 11 days of work, Claude generated 13 million lines of Lean code and proved a total of 30,300 theorems. Of these, 29,500 were actually used in the final proof. This is said to be more than five times the size of "Mathlib," the foundational library for Lean-formulated mathematics.

The computational resources required for the work are estimated to be around 6 billion output tokens. The model used was a general-purpose in-house research model with performance roughly comparable to Claude Fable 5.1.

A Candid Disclosure of the Process: "Many Failures"

What is interesting from a researcher's perspective in this results report is that Anthropic itself candidly admits that things didn't go smoothly from the start. According to the company, initial attempts stalled many times. The agent accumulated too much local contextual information, lost track of what had already been proven, repeated the same work, and became unable to cooperate effectively.

These failed initial attempts contributed approximately 7% to the non-standard parts (the actual code, not boilerplate) of the final proof, but the entire workflow only became stable after migrating to the "Prove2Me" platform.

The Importance of "Prove2Me," an External Academic Infrastructure

Understanding this achievement is crucial, as it involves the existence of "Prove2Me," an external collaborative platform not developed in-house by Anthropic. Developed by Tianyi Peng and colleagues at Columbia University, this open collaborative platform centers on the concept of "theorems and directed acyclic graphs (DAGs) of the objects of proof."

This platform doesn't require a single agent to memorize the entire proof. Instead, it visualizes unresolved dependencies, allowing agents to select manageable nodes (parts to be proven) from the graph, prove them individually, and then make the results available to other agents. Furthermore, by separating the theorem description from the proof implementation, it enables more efficient distribution of the Lean compilation process. The existence of this existing open academic infrastructure is a key point, as it made this achievement possible—something Anthropic couldn't have accomplished with its own technological capabilities alone.

A Careful Evaluation by Mathematician Kevin Buzzard

Kevin Buzzard, a mathematician at Imperial College London (who himself led the Fermat's Last Theorem formalization project in Lean), who verified this result, commented, "According to Anthropic researchers, this astonishing achievement of automated formalization took only 11 days, and it proves Fermat's Last Theorem without making any assumptions other than mathematical axioms."

He further added, "If automated formalization of Fermat's Last Theorem is possible at this point, we will have taken a significant step towards the automated formalization of the entirety of modern mathematical literature. Such automated formalization techniques will create new tools, uncover errors in the entirety of current mathematics, and reduce the burden on reviewers."

An Interesting Parallel with OpenAI's Astra

This result can be compared to the previously discussed achievement of OpenAI's Astra in solving an unsolved mathematical problem. While Astra's case represented a truly novel mathematical discovery outside of existing frameworks, Claude's achievement is a different kind of contribution: translating already proven results into a machine-verifiable form. However, both share a common thread: the significant trend of AI dramatically accelerating specific stages of mathematical research that were previously bottlenecked by human experts.

What Researchers Should Consider

The most important lesson from this achievement is that AI's contribution to mathematical research is only realized through the combination of its capabilities with supporting external, open academic infrastructure (Prove2Me, Mathlib). This suggests that when AI companies claim their technological superiority, they must carefully consider the extent to which that superiority is proprietary and to what extent it relies on open, shared infrastructure.

The question remains: to what extent can this type of automated formalization technology be applied to the entirety of modern mathematical literature? The question then becomes whether academic communities like Mathlib will actually incorporate the 29,500 interim theorems generated into their own foundation. As Buzzard points out, this will be an important test to determine whether this technology is a "one-off achievement" or a "reusable infrastructure."

AnthropicClaude数学LeanAI/ML

Anthropic's new deal promises $35 billion in "unraveled funds," highlighting the race to raise capital.

On September 1st, Anthropic signed a $35 billion computing resources contract with NVIDIA-backed Lambda, marking its second infrastructure contract following a $45 billion deal with Nscale a week earlier. This article will examine, from an accounting perspective, the structure in which NVIDIA plays three roles—lessee, chip supplier, and investor in Lambda—as well as the planned operation of the Hut 8 facility in Texas in Q1 2027, analyst Neil Campling's analysis that Anthropic has "debt for unraised funds" and that an IPO is its only exit strategy, and the cyclical structure similar to that of SB Energy, with its annual net loss of $42 billion and accumulating massive contracts.

A $35 Billion Promise for "Unraised Funds"—Anthropic's New Contract Threatens Competition for Funding

Multiple media outlets reported on September 1st that Anthropic had signed a $35 billion computing resources contract with Lambda, a cloud provider backed by NVIDIA. This is Anthropic's second major infrastructure contract in recent years. As an accountant, I want to examine the financial position the company is increasingly finding itself in as these contracts accumulate.

A Complex Structure: NVIDIA as the Lessee, Lambda as the Supplier

First, let's clarify the relationships between the parties involved in this contract. The contract centers around a data center being developed in Nueces County, Texas, by Hut 8 (a company that previously operated cryptocurrency mining operations and has now shifted to AI data center management).

According to reports, NVIDIA holds the lease agreement for this facility, while Lambda installs NVIDIA chips and provides computing power to Anthropic, creating a multi-party structure. The facility is expected to provide approximately 350 megawatts of capacity. NVIDIA simultaneously plays multiple roles: chip supplier, facility lessee, and investor in Lambda.

The Speed ​​of Two Massive Infrastructure Contracts in One Week

What's remarkable about this contract with Lambda is its timing. According to reports, just one week prior, Anthropic had already signed a $45 billion lease agreement with Nscale, a UK-based AI infrastructure company, securing over 400 megawatts of computing power at a data center facility in West Virginia.

In other words, within just about a week, they've secured infrastructure contracts totaling nearly $80 billion in quick succession. This move further expands on Anthropic's previous infrastructure investments (including a $50 billion deal with Fluidstack, over $100 billion with AWS, and Theseus Infrastructure).

A Candid Point: "A Commitment to Unraised Funds"

Financial analyst Neil Campling's analysis of this news is interesting. He describes Anthropic as having signed a $35 billion computing resource debt for funds not yet raised, suggesting that an IPO (Initial Public Offering) would be the "only way out" to fulfill this massive commitment.

This point directly connects to the previously discussed context of Anthropic's IPO preparations (a $2 trillion valuation and a $30 trillion TAM claim). The scale of the infrastructure contracts the company is accumulating appears to exceed the scope of its already secured funds, taking on a stronger character of forward-looking investment based on future fundraising.

The Structural Feature of NVIDIA Sitting on Both Sides of the Deal

Campling further notes NVIDIA's unique position in this series of deals. NVIDIA is involved on "both sides" of the deal, both as an investor in Lambda and as a tenant of data center facilities.

This is in the same context as NVIDIA's previous financial strategies—the $105 billion guarantee to OpenAI, the $12.2 billion warrant grant to Google, the $500 billion fundraising plan, and the "AI Compute Partnership" which was temporarily suspended following criticism of "circular finance." It can be understood that NVIDIA consistently pursues a strategy of securing demand for its chips simultaneously from multiple channels by positioning itself at the nexus of every deal surrounding AI infrastructure.

The Limits of Transparency: "Non-Disclosure" of Contract Terms

A point to note in this series of reports is that the specific terms of this $35 billion contract—the contract period, the number of GPUs, the payment schedule, and the actual scale of computing power—have not been disclosed. Hut 8 is said to expect the initial energy supply to the Beacon Point facility to begin in the first quarter of 2027, and the first data hole of Phase 2 to become operational in the second quarter of 2028. This is one of the few concrete pieces of information that shows a rough timeline until the actual computing power is provided.

Points to Consider from an Accountant's Perspective

While these massive infrastructure contracts that Anthropic is accumulating in a short period of time can be understood as aggressive upfront investments to meet rapidly growing demand, it also indicates that its financial backing is increasingly dependent on future fundraising (especially the success of an IPO) beyond the capital it currently has secured.

As previously discussed, Anthropic is accumulating these kinds of tens of billions of dollars in long-term contracts while simultaneously facing a massive annual net loss of $42 billion. This scenario of "massive future commitments at a stage where revenue has not yet caught up" can be seen as part of a cyclical funding structure similar to that outlined in SB Energy's IPO application documents.

When Anthropic actually proceeds with its IPO, it will be necessary to closely monitor how this series of infrastructure contracts are disclosed in the prospectus as liabilities or future payment obligations, and to what extent investors will deem this "massive debt promised before fundraising" acceptable.

AnthropicNVIDIAAIインフラ循環金融ファイナンス
Advertisement300 × 250