« Volver al listado

Anthropic

Anthropic Claude Code: vulnerabilidades y CVE

Anthropic Claude Code tiene 29 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE29
Últimos 12 meses22
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-103012Baja (2)0.10%—30 sept 2026
Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the…
CVE-2026-73614Alta (8.7)0.68%—13 ago 2026
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content…
CVE-2026-55607Alta (7.7)0.69%—29 jun 2026
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git…
CVE-2026-46406Media (4.4)0.15%—29 jun 2026
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink…
CVE-2026-54316Media (6)0.52%—23 jun 2026
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled…
CVE-2026-40068Alta (7.7)0.56%—5 may 2026
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a…
CVE-2026-39861Alta (7.7)0.80%—21 abr 2026
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently…
CVE-2026-35603Media (5.4)0.15%—17 abr 2026
Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory…
CVE-2026-33068Alta (7.7)0.57%—20 mar 2026
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace…
CVE-2026-25725Alta (7.7)0.64%—6 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup.…
CVE-2026-25724Baja (2.3)0.60%—6 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied…
CVE-2026-25723Alta (7.7)0.48%—6 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file write restrictions.…
CVE-2026-25722Alta (7.7)0.63%—6 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate…
CVE-2026-24887Alta (7.7)0.65%—3 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the…
CVE-2026-24053Alta (7.7)0.53%—3 feb 2026
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current…
CVE-2026-24052Alta (7.1)0.44%—3 feb 2026
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith()…
CVE-2026-21852Media (5.3)28%—21 ene 2026
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed…
CVE-2025-66032Alta (8.7)0.69%—3 dic 2025
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary…
CVE-2025-64755Alta (8.7)0.55%—21 nov 2025
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.…
CVE-2025-65099Alta (7.7)0.51%—19 nov 2025
Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the…
CVE-2025-59829Baja (2.3)0.45%—3 oct 2025
Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a…
CVE-2025-59536Alta (8.7)27%—3 oct 2025
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a…
CVE-2025-59828Alta (7.7)0.37%—24 sept 2025
Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed when running yarn --version. This could lead to a bypass of the…
CVE-2025-59041Alta (8.7)0.55%—10 sept 2025
Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger…
CVE-2025-58764Alta (8.7)0.55%—10 sept 2025
Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code confirmation prompt to trigger execution of an untrusted command.…
CVE-2025-55284Alta (7.1)0.48%—16 ago 2025
Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an…
CVE-2025-54795Alta (8.7)1.0%—5 ago 2025
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably…
CVE-2025-54794Alta (7.7)1.4%—5 ago 2025
Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files…
CVE-2025-52882Alta (8.8)0.34%—24 jun 2025
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution19
  2. T1059 Command and Scripting Interpreter14
  3. T1005 Data from Local System3
  4. T1068 Exploitation for Privilege Escalation2
  5. T1189 Drive-by Compromise2
  6. T1059.004 Unix Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Anthropic