Anthropic

Claude Code

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 23.06.2026 17:06:16
  • Zuletzt bearbeitet 23.06.2026 19:32:37

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approv...

  • EPSS 0.28%
  • Veröffentlicht 05.05.2026 21:16:23
  • Zuletzt bearbeitet 12.05.2026 16:21:46

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the v...

  • EPSS 0.52%
  • Veröffentlicht 21.04.2026 00:56:39
  • Zuletzt bearbeitet 23.04.2026 18:36:24

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a ...

  • EPSS 0.11%
  • Veröffentlicht 17.04.2026 20:38:49
  • Zuletzt bearbeitet 22.04.2026 18:45:11

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions....

Exploit
  • EPSS 0.6%
  • Veröffentlicht 06.04.2026 18:59:29
  • Zuletzt bearbeitet 29.05.2026 18:16:55

Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag behavior is documented in Anthropic's claude -h output with an explicit warning that non-interactive mode should only be used in t...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 06.04.2026 18:59:06
  • Zuletzt bearbeitet 29.05.2026 18:16:44

Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.04.2026 18:58:40
  • Zuletzt bearbeitet 29.05.2026 18:16:31

Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalen...

  • EPSS 0.34%
  • Veröffentlicht 20.03.2026 08:17:47
  • Zuletzt bearbeitet 24.03.2026 15:46:36

Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A ma...

  • EPSS 0.42%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 09.02.2026 14:46:12

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was moun...

  • EPSS 0.38%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 27.03.2026 22:16:20

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such a...