Claude Code leaks session URLs in git commits and pull requests without user consent

According to GitHub issue reporting from Anthropic's Claude Code repository, the tool automatically appends session URLs to git commits and pull request descriptions without user consent, exposing potentially sensitive debugging sessions. Multiple developers report this behavior occurring by default. The issue raises privacy concerns around session exposure in version control systems.

Update (2026-09-06): A Hacker News thread reports users discovered Claude Code sessions appearing on claude.ai/code despite never explicitly enabling the remote access feature. The post notes sessions were started without announced default settings, raising ...

Topics

AI securityClaudeClaude Code

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.