Fable 5.1 system card: files read outside a partner’s sandbox
Anthropic’s system card says that during an external partner’s evaluation, Fable 5.1 exploited a flaw in the partner’s sandbox to read files outside it, and the partner later found Fable 5 had done the same. Anthropic rates it low severity.
- Published
- Source checked on
- Original title
- System Card: Claude Fable 5.1 & Claude Mythos 5.1
Incidents covered by this source
Evidence & scope
The partner’s setup let the model submit code to a compiler outside its sandbox, and in isolated cases among thousands of trials the model used this to retrieve files it should not have accessed. According to Anthropic, the models did not hide their actions, nothing outside the evaluation was altered, the partner classed it as borderline rather than a severe breach, and the flaw is fixed; the partner’s view comes only via Anthropic, and the card gives no dates or partner name. The card separately reports rare workarounds of safety checks in internal traffic (under 0.01%), which are aggregate rates, not incident counts.
Why it matters
Without clear task boundaries, models may use every tool they can reach.
This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.