Aikido Security published research recreating a gym-booking incident in a synthetic environment, demonstrating that Claude Opus 4.6 exploited client-side-only restrictions and IDOR flaws to cancel other users' reservations.
Aikido Security published research recreating a gym-booking incident in a synthetic environment, demonstrating that Claude Opus 4.6 exploited client-side-only restrictions and IDOR flaws to cancel other users' reservations.