VendorsAnthropicclaude_codeall versions
Vulnerabilities

Anthropic Claude Code

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2026-39861
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
Published 2026-04-21 · Analyzed
10.0EPSS 0.008
CVE-2026-25725
Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
Published 2026-02-06 · Analyzed
10.0EPSS 0.006
CVE-2025-54795
Claude Code echo command allowed bypass of user approval prompt for command execution
Published 2025-08-05 · Analyzed
9.8EPSS 0.010
CVE-2025-66032
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
Published 2025-12-03 · Analyzed
9.8EPSS 0.007
CVE-2025-64755
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Published 2025-11-21 · Analyzed
9.8EPSS 0.006
CVE-2025-58764
Claude Code rg command had Command Injection that allowed bypass of user approval prompt for command execution
Published 2025-09-10 · Analyzed
9.8EPSS 0.005
CVE-2025-59041
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
Published 2025-09-10 · Analyzed
9.8EPSS 0.005
CVE-2025-65099
Claude Code vulnerable to command execution prior to startup trust dialog
Published 2025-11-19 · Analyzed
9.8EPSS 0.005
CVE-2025-59828
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
Published 2025-09-24 · Analyzed
9.8EPSS 0.004
CVE-2025-54794
Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
Published 2025-08-05 · Analyzed
9.1EPSS 0.014
CVE-2026-25722
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
Published 2026-02-06 · Analyzed
9.1EPSS 0.006
CVE-2026-54316
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Published 2026-06-23 · Analyzed
9.1EPSS 0.005
CVE-2025-59536
Claude Code's startup trust dialog could lead to Command Execution attack
Published 2025-10-03 · Analyzed
8.8EPSS 0.272
CVE-2026-55607
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Published 2026-06-29 · Analyzed
8.8EPSS 0.007
CVE-2026-24887
Claude Code has a Command Injection in find Command Bypasses User Approval Prompt
Published 2026-02-03 · Analyzed
8.8EPSS 0.006
CVE-2026-33068
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Published 2026-03-20 · Analyzed
8.8EPSS 0.006
CVE-2026-40068
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
Published 2026-05-05 · Analyzed
8.8EPSS 0.006
CVE-2026-24053
Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes
Published 2026-02-03 · Analyzed
7.7EPSS 0.005
CVE-2026-25723
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
Published 2026-02-06 · Analyzed
7.7EPSS 0.005
CVE-2026-21852
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Published 2026-01-21 · Analyzed
7.5EPSS 0.279
CVE-2026-25724
Claude Code Has Permission Deny Bypass Through Symbolic Links
Published 2026-02-06 · Modified
7.5EPSS 0.006
CVE-2025-55284
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
Published 2025-08-16 · Analyzed
7.5EPSS 0.005
CVE-2026-24052
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
Published 2026-02-03 · Analyzed
7.4EPSS 0.004
CVE-2026-35603
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Published 2026-04-17 · Analyzed
7.3EPSS 0.002
CVE-2025-59829
Claude Code: Permission deny bypass is possible through symlink
Published 2025-10-03 · Analyzed
6.5EPSS 0.004
CVE-2026-46406
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
Published 2026-06-29 · Analyzed
6.1EPSS 0.002