Browse all 36 CVE security advisories affecting anthropics. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Anthropics operates as an artificial intelligence research laboratory, primarily developing large language models like Claude for enterprise and consumer applications. With twenty-eight recorded Common Vulnerabilities and Exposures (CVEs), the organization’s historical attack surface has predominantly featured server-side request forgery and cross-site scripting flaws within its web interfaces and API gateways. These vulnerabilities typically stem from insufficient input validation in legacy backend services rather than core model architecture failures. Notably, the company has maintained a relatively stable security posture compared to broader industry trends, avoiding major data breaches or widespread exploitation incidents. Most disclosed issues have been resolved through routine patching cycles, indicating a mature incident response framework. The focus remains on securing infrastructure supporting model training and inference, ensuring that the primary risk vectors are contained within standard web application layers rather than compromising the underlying AI systems themselves.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-59041 | Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email — claude-code CWE-94 | 8.8AI | High AI | 2025-09-10 |
| CVE-2025-58764 | Claude Code rg command had Command Injection that allowed bypass of user approval prompt for command execution — claude-code CWE-94 | 8.8AI | High AI | 2025-09-10 |
| CVE-2025-55284 | Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code — claude-code CWE-78 | 9.4AI | Critical AI | 2025-08-16 |
| CVE-2025-54794 | Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access — claude-code CWE-22 | 9.1AI | Critical AI | 2025-08-05 |
| CVE-2025-54795 | Claude Code echo command allowed bypass of user approval prompt for command execution — claude-code CWE-78 | 8.3AI | High AI | 2025-08-05 |
| CVE-2025-52882 | Claude Code IDE extensions allow websocket connections from arbitrary origins — claude-code CWE-1385 | 7.1AI | High AI | 2025-06-24 |
This page lists every published CVE security advisory associated with anthropics. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.