Anthropic

Claude Code

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.04.2026 18:58:40
  • Zuletzt bearbeitet 29.05.2026 18:16:31

Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalen...

  • EPSS 0.34%
  • Veröffentlicht 20.03.2026 08:17:47
  • Zuletzt bearbeitet 24.03.2026 15:46:36

Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A ma...

Medienbericht
  • EPSS 0.47%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 09.02.2026 14:46:12

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was moun...

  • EPSS 0.38%
  • Veröffentlicht 06.02.2026 18:16:00
  • Zuletzt bearbeitet 27.03.2026 22:16:20

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such a...

  • EPSS 0.36%
  • Veröffentlicht 06.02.2026 18:15:59
  • Zuletzt bearbeitet 09.02.2026 14:51:42

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate into sensitive directories like .c...

  • EPSS 0.26%
  • Veröffentlicht 06.02.2026 18:15:59
  • Zuletzt bearbeitet 09.02.2026 14:50:15

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file write restrictions. This vulnerability enabled writin...

  • EPSS 0.57%
  • Veröffentlicht 03.02.2026 20:50:25
  • Zuletzt bearbeitet 06.02.2026 20:19:47

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting...

  • EPSS 0.46%
  • Veröffentlicht 03.02.2026 20:49:59
  • Zuletzt bearbeitet 06.02.2026 20:24:38

Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user p...

  • EPSS 0.34%
  • Veröffentlicht 03.02.2026 20:49:41
  • Zuletzt bearbeitet 06.02.2026 20:28:53

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted do...

  • EPSS 23.52%
  • Veröffentlicht 21.01.2026 20:42:06
  • Zuletzt bearbeitet 02.02.2026 15:04:41

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repos...