Skip to content

[Bug] Cyber Verification Program status unexpectedly changed to "In review" during authorized security research session #86867

Description

@ahmetmelihtunc-ctrl

Hi Anthropic Support team,

I'm a bug bounty hunter / security researcher. I was previously approved under the Cyber Verification Program for security research use cases (pentesting, red teaming, bug bounty).

During a Claude Code session today, my Cyber Verification Program status changed from Approved to "In review" after a message was flagged mid-task by the real-time cyber safeguards system.

Context of the flagged task:
I was working through PortSwigger's Web Security Academy labs — officially licensed educational content in an authorized, isolated lab environment. Specifically, a server-side prototype pollution lab whose documented intended solution path involves triggering RCE and reading a secret file within the sandboxed lab container. This is the official PortSwigger solution, not an attack against any third-party or production system.

Requests:

Please confirm whether my previous approval remains valid, or whether this flag triggers a new review requirement.
If a new review is required, let me know what additional information I can provide to expedite it (e.g., program enrollment details, lab URLs, session logs).
If possible, please advise whether flagged-but-authorized educational lab work can be whitelisted to avoid interrupting future sessions.

Thanks for your help.

Environment Info

Platform: darwin
Terminal: iTerm.app
Version: 2.1.228
Feedback ID: dabd0561-cd3c-484b-a541-e710021709caHi Anthropic Support team,

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions