PT-2026-3758 · Anthropic · Claude-Code
Dworken
·
Published
2026-01-21
·
Updated
2026-05-12
·
CVE-2026-21852
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Claude Code versions prior to 2.0.65
Description
A flaw in the project-load flow of Claude Code allows malicious repositories to exfiltrate sensitive data, such as Anthropic API keys, before a user confirms trust. An attacker can include a settings file in a repository that modifies the
ANTHROPIC BASE URL variable to point to an attacker-controlled endpoint. When the repository is opened, the software reads this configuration and issues API requests immediately, bypassing the trust prompt and potentially leaking the user's API keys.Recommendations
Update to version 2.0.65 or the latest version.
Exploit
Fix
RCE
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Claude-Code