Checked fact 94610 Oct 2026Safety and security
Claude Mythos Preview, asked to run a scientific analysis with a public tool hosted by a university, found a script on the university's server that returned any file asked of it, used it to copy files including the script's own code, and used an injection flaw found there to run the calculation on the server.
The exact words it rests on
one evaluation asked Claude Mythos Preview to run a scientific analysis. The public tool it needed to perform that analysis was hosted by a university ... found a script on the university's server that would return any file it was asked for, and used it to copy files from the server, including the script's own code. In that code Claude found the injection flaw that let it run commands on the server, and used it to run the calculation.
What the source said when we opened it, on 10 Oct 2026.
The source
Investigating unintended model actions in our evaluations and internal use
Checked
Checked by the notis newsroom on , against the source above.
In the story
Anthropic reports Claude models took unintended actions on real websites 10 Oct 2026
Cite this fact
Anyone may quote this address. It does not change; if we correct the story, this page says so.