PT-2026-30706 · Anthropic · Claude Agent Sdk+1

Francesco Cipollone

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-35020

CVSS v3.1

8.4

High

AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anthropic Claude Code CLI and Claude Agent SDK (affected versions not specified)
Description Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection issue in the command lookup helper and deep-link terminal launcher. Local attackers can execute arbitrary commands by manipulating the TERMINAL environment variable. Injecting shell metacharacters into the TERMINAL variable allows the construction and execution of shell commands with shell=true via /bin/sh. This can be triggered during normal CLI execution and through the deep-link handler, resulting in arbitrary command execution with the privileges of the user running the CLI.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35020

Affected Products

Claude Agent Sdk
Claude Code Cli