Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

anthropics — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting anthropics. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Anthropics operates as an artificial intelligence research laboratory, primarily developing large language models like Claude for enterprise and consumer applications. With twenty-eight recorded Common Vulnerabilities and Exposures (CVEs), the organization’s historical attack surface has predominantly featured server-side request forgery and cross-site scripting flaws within its web interfaces and API gateways. These vulnerabilities typically stem from insufficient input validation in legacy backend services rather than core model architecture failures. Notably, the company has maintained a relatively stable security posture compared to broader industry trends, avoiding major data breaches or widespread exploitation incidents. Most disclosed issues have been resolved through routine patching cycles, indicating a mature incident response framework. The focus remains on securing infrastructure supporting model training and inference, ensuring that the primary risk vectors are contained within standard web application layers rather than compromising the underlying AI systems themselves.

CVE ID Title CVSS Severity Published
CVE-2026-47751 Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration — claude-code-action CWE-78 - - 2026-07-16
CVE-2026-55407 Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation — buffa CWE-400 - - 2026-07-16
CVE-2026-55406 Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref — buffa CWE-200 - - 2026-07-16
CVE-2026-55607 Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution — claude-code CWE-22 - - 2026-06-29
CVE-2026-46406 Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write — claude-code CWE-59 - - 2026-06-29
CVE-2026-54316 Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch — claude-code CWE-183 - - 2026-06-23
CVE-2026-44470 Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMService — claude-code CWE-59 - - 2026-05-13
CVE-2026-44467 Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions — claude-code CWE-297 - - 2026-05-13
CVE-2026-40068 Claude Code arbitrary code execution via git worktree commondir trust dialog bypass — claude-code CWE-20 7.0 - 2026-05-05
CVE-2026-41686 Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool — anthropic-sdk-typescript CWE-732 5.5 - 2026-05-04
CVE-2026-39861 Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace — claude-code CWE-22 8.8AI High AI 2026-04-21
CVE-2026-35603 Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows — claude-code CWE-426 7.3AI High AI 2026-04-17
CVE-2026-34451 Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories — anthropic-sdk-typescript CWE-22 8.1 - 2026-03-31
CVE-2026-34450 Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool — anthropic-sdk-python CWE-276 4.4 - 2026-03-31
CVE-2026-34452 Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape — anthropic-sdk-python CWE-59 8.4 - 2026-03-31
CVE-2026-33068 Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File — claude-code CWE-807 8.8 - 2026-03-20
CVE-2026-25725 Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json — claude-code CWE-501 8.4AI High AI 2026-02-06
CVE-2026-25724 Claude Code Has Permission Deny Bypass Through Symbolic Links — claude-code CWE-61 6.5AI Medium AI 2026-02-06
CVE-2026-25723 Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions — claude-code CWE-20 9.4AI Critical AI 2026-02-06
CVE-2026-25722 Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection — claude-code CWE-20 7.5AI High AI 2026-02-06
CVE-2026-24887 Claude Code has a Command Injection in find Command Bypasses User Approval Prompt — claude-code CWE-78 8.3AI High AI 2026-02-03
CVE-2026-24053 Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes — claude-code CWE-22 6.5AI Medium AI 2026-02-03
CVE-2026-24052 Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains — claude-code CWE-601 7.5AI High AI 2026-02-03
CVE-2026-21852 Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation — claude-code CWE-522 6.5AI Medium AI 2026-01-21
CVE-2025-66032 Claude Code Command Validation Bypass Allows Arbitrary Code Execution — claude-code CWE-77 8.4AI High AI 2025-12-03
CVE-2025-64755 @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes — claude-code CWE-78 6.2 - 2025-11-21
CVE-2025-65099 Claude Code vulnerable to command execution prior to startup trust dialog — claude-code CWE-94 8.8AI High AI 2025-11-19
CVE-2025-59829 Claude Code: Permission deny bypass is possible through symlink — claude-code CWE-61 4.3AI Medium AI 2025-10-03
CVE-2025-59536 Claude Code's startup trust dialog could lead to Command Execution attack — claude-code CWE-94 8.8AI High AI 2025-10-03
CVE-2025-59828 Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions — claude-code CWE-829 9.1AI Critical AI 2025-09-24

This page lists every published CVE security advisory associated with anthropics. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.