vciy

CVEs we hold for Anthropics

Records whose assigning authority named Anthropics as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-55607Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Executionanthropics claude-code
CVE-2026-55407Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocationanthropics buffa
CVE-2026-55406Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Derefanthropics buffa
CVE-2026-54316Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchanthropics claude-code
CVE-2026-47751Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltrationanthropics claude-code-action
CVE-2026-46406Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Writeanthropics claude-code
CVE-2026-44470Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMServiceanthropics claude-code
CVE-2026-44467Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessionsanthropics claude-code
CVE-2026-41686Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Toolanthropics anthropic-sdk-typescript
CVE-2026-40068Claude Code arbitrary code execution via git worktree commondir trust dialog bypassanthropics claude-code
CVE-2026-39861Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspaceanthropics claude-code
CVE-2026-35603Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windowsanthropics claude-code
CVE-2026-34452Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escapeanthropics anthropic-sdk-python
CVE-2026-34451Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directoriesanthropics anthropic-sdk-typescript
CVE-2026-34450Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Toolanthropics anthropic-sdk-python
CVE-2026-33068Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings Fileanthropics claude-code
CVE-2026-25725Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.jsonanthropics claude-code
CVE-2026-25724Claude Code Has Permission Deny Bypass Through Symbolic Linksanthropics claude-code
CVE-2026-25723Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictionsanthropics claude-code
CVE-2026-25722Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protectionanthropics claude-code
CVE-2026-24887Claude Code has a Command Injection in find Command Bypasses User Approval Promptanthropics claude-code
CVE-2026-24053Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writesanthropics claude-code
CVE-2026-24052Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domainsanthropics claude-code
CVE-2026-21852Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmationanthropics claude-code
CVE-2025-66032Claude Code Command Validation Bypass Allows Arbitrary Code Executionanthropics claude-code
CVE-2025-65099Claude Code vulnerable to command execution prior to startup trust dialoganthropics claude-code
CVE-2025-64755@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writesanthropics claude-code
CVE-2025-59829Claude Code: Permission deny bypass is possible through symlinkanthropics claude-code
CVE-2025-59828Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versionsanthropics claude-code
CVE-2025-59536Claude Code's startup trust dialog could lead to Command Execution attackanthropics claude-code
CVE-2025-59041Claude Code vulnerable to arbitrary code execution caused by maliciously configured git emailanthropics claude-code
CVE-2025-58764Claude Code rg command had Command Injection that allowed bypass of user approval prompt for command executionanthropics claude-code
CVE-2025-55284Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Codeanthropics claude-code
CVE-2025-54795Claude Code echo command allowed bypass of user approval prompt for command executionanthropics claude-code
CVE-2025-54794Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file accessanthropics claude-code
CVE-2025-52882Claude Code IDE extensions allow websocket connections from arbitrary originsanthropics claude-code

36 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.