Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dworken

#38929of 56,326
7.5Total CVSS
Vulnerabilities · 1
PT-2026-3758
7.5
2026-01-21
Anthropic · Claude-Code · CVE-2026-21852
**Name of the Vulnerable Software and Affected Versions** Claude Code versions prior to 2.0.65 **Description** A flaw in the project-load flow allows malicious repositories to exfiltrate sensitive data, such as Anthropic API keys, before a user confirms trust in the project. An attacker can include a settings file in a repository that modifies the `ANTHROPIC BASE URL` variable to point to an attacker-controlled endpoint. When the repository is opened, the software reads this configuration and issues API requests immediately, bypassing the trust prompt and potentially leaking the user's API keys. **Recommendations** Update to version 2.0.65 or the latest available version.