Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
The release includes an embedded MCP server that exposes Spring project analytics to AI coding assistants, along with first-class support for Spring AI and automated property refactoring.