CVE Tools

@anthropic-ai/claude-code

21 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for @anthropic-ai/claude-code, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

@anthropic-ai/claude-code CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
@anthropic-ai/claude-code CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-083
2025-094
2025-102
2025-112
2025-121
2026-011
2026-027
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1053%
  • High632%
  • Medium316%

Latest CVEs

The 15 most recently published vulnerabilities affecting @anthropic-ai/claude-code.

  1. CVE-2026-25725Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json10.0
  2. CVE-2026-25724Claude Code Has Permission Deny Bypass Through Symbolic Links7.5
  3. CVE-2026-25723Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions6.5
  4. CVE-2026-25722Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection9.1
  5. CVE-2026-24887Claude Code has a Command Injection in find Command Bypasses User Approval Prompt8.8
  6. CVE-2026-24053Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes6.5
  7. CVE-2026-24052Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains7.4
  8. CVE-2026-21852Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation7.5
  9. CVE-2025-66032Claude Code Command Validation Bypass Allows Arbitrary Code Execution9.8
  10. CVE-2025-64755@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes9.8
  11. CVE-2025-65099Claude Code vulnerable to command execution prior to startup trust dialog9.8
  12. CVE-2025-59829Claude Code: Permission deny bypass is possible through symlink6.5
  13. CVE-2025-59536Claude Code's startup trust dialog could lead to Command Execution attack8.8
  14. CVE-2025-59828Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions9.8
  15. CVE-2025-59041Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store