Anthropic

Claude Code

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 09.02.2026 14:46:12

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was moun...

  • EPSS 0.06%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 09.02.2026 14:47:41

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such a...

  • EPSS 0.11%
  • Veröffentlicht 06.02.2026 18:15:59
  • Zuletzt bearbeitet 09.02.2026 14:50:15

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file write restrictions. This vulnerability enabled writin...

  • EPSS 0.15%
  • Veröffentlicht 06.02.2026 18:15:59
  • Zuletzt bearbeitet 09.02.2026 14:51:42

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate into sensitive directories like .c...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 20:50:25
  • Zuletzt bearbeitet 06.02.2026 20:19:47

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting...

  • EPSS 0.02%
  • Veröffentlicht 03.02.2026 20:49:59
  • Zuletzt bearbeitet 06.02.2026 20:24:38

Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user p...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 20:49:41
  • Zuletzt bearbeitet 06.02.2026 20:28:53

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted do...

  • EPSS 0.02%
  • Veröffentlicht 21.01.2026 20:42:06
  • Zuletzt bearbeitet 02.02.2026 15:04:41

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repos...

  • EPSS 0.06%
  • Veröffentlicht 03.12.2025 18:16:54
  • Zuletzt bearbeitet 05.12.2025 16:29:42

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploit...

  • EPSS 0.1%
  • Veröffentlicht 21.11.2025 01:13:05
  • Zuletzt bearbeitet 04.12.2025 18:03:51

Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in ver...