claude code just tried connecting to someone else's database (!!!)
it used my password, but on a random neon aws db
I tried connect to that database (ep-white-lake-a______v-pooler.us-east-2. aws. neon. tech) via psql, and it actually exists!
and no, that's not mine, i never used neon before, not even on another repo on my laptop (afaik)
if .envs are leaking data via llm's we are cooked
I asked why it did that, and it said it hallucinated - but from a real URL. imagine if the pwd was actually valid?!
for
@AnthropicAI @claudeai: this is claude code Version: 2.0.76, Login method: Claude Max Account, Model: Default Opus 4.5, IDE: Installed VS Code extension (Windsurf)