PT-2026-35681 · Erlichliu · Claude Agent Sdk

Brucejin

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7235

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ErlichLiu claude-agent-sdk-master versions up to b185aa7ff0d864581257008077b4010fca1747bf
Description A path traversal issue exists in the 'app/api/agent-output/route.ts' file. A remote attacker can exploit this by manipulating the outputFile argument, allowing unauthorized access to files or directories outside the intended folder.
Recommendations As a temporary workaround, restrict access to the 'app/api/agent-output/route.ts' endpoint or avoid using the outputFile argument until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7235

Affected Products

Claude Agent Sdk