@anthropic-ai/claude-code vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-46406Medium@anthropic-ai/claude-code: @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File WriteCVE-2026-54316Medium@anthropic-ai/claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchCVE-2026-40068High@anthropic-ai/claude-code: Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code ExecutionCVE-2026-39861High@anthropic-ai/claude-code: Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspaceCVE-2026-35603Medium@anthropic-ai/claude-code: Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsCVE-2026-33068High@anthropic-ai/claude-code: Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings FileCVE-2026-25725High@anthropic-ai/claude-code: Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.jsonCVE-2026-25724Low@anthropic-ai/claude-code: Claude Code has Permission Deny Bypass Through Symbolic LinksCVE-2026-25723High@anthropic-ai/claude-code: Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write RestrictionsCVE-2026-25722High@anthropic-ai/claude-code: Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write ProtectionCVE-2026-24887High@anthropic-ai/claude-code: Claude Code has a Command Injection in find Command Bypasses User Approval PromptCVE-2026-24053High@anthropic-ai/claude-code: Claude Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File WritesCVE-2026-24052High@anthropic-ai/claude-code: Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled DomainsCVE-2026-21852Medium@anthropic-ai/claude-code: Claude Code Leaks Data via Malicious Environment Configuration Before Trust ConfirmationCVE-2025-66032High@anthropic-ai/claude-code: Claude Code Command Validation Bypass Allows Arbitrary Code ExecutionCVE-2025-64755High@anthropic-ai/claude-code: @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File WritesCVE-2025-65099High@anthropic-ai/claude-code: Claude Code vulnerable to command execution prior to startup trust dialogCVE-2025-59829Low@anthropic-ai/claude-code: Claude Code permission deny bypass through symlinkCVE-2025-59536High@anthropic-ai/claude-code: Claude Code can execute commands prior to the startup trust dialog CVE-2025-59828High@anthropic-ai/claude-code: Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn VersionsCVE-2025-59041High@anthropic-ai/claude-code: Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email CVE-2025-58764High@anthropic-ai/claude-code: Claude Code rg vulnerability does not protect against approval prompt bypassGHSA-PH6W-F82W-28W6High@anthropic-ai/claude-code: Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup WarningCVE-2025-55284High@anthropic-ai/claude-code: Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude CodeCVE-2025-54795High@anthropic-ai/claude-code: Claude Code echo command allowed bypass of user approval prompt for command execution

Stop the waste.
Protect your environment with Kodem.