Claude found a real Chisel tunneling bug, then its safety filter blocked the fix

Mainfurr · reddit · 2026-10-10

A Reddit user asked Claude to help set up a Chisel reverse tunnel on a homelab. Claude independently read Chisel's source, discovered a real vulnerability — a malicious server can redirect a reverse tunnel to arbitrary destinations on the client's LAN because the client doesn't validate the setup — and began building a test.

Then the safety filter kicked in: any new chat containing the vulnerability description is instantly refused. The author argues this is security theater: the disclosure already happened, so the filter only obstructs legitimate follow-through — testing, verifying, and writing a bug report — while a bad actor with the same description can build the malicious server themselves.

The post calls on Anthropic to fix these false positives instead of forcing paying customers to rephrase legitimate security work, and asks other users to report similar cases.

Original post →

More from Models

Models channel →