PT-2026-29380 · Anthropic · Claude Sdk For Python

·

CVE-2026-34452

·

Published

2026-03-31

·

Updated

2026-04-01

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Claude SDK for Python versions 0.86.0 through 0.86.999
Description The Claude SDK for Python, used to access the Claude API, had a flaw in the async local filesystem memory tool between versions 0.86.0 and before 0.87.0. The tool validated file paths within a sandbox, but then used the unvalidated path for file operations. This allowed a local attacker who could write to the memory directory to potentially escape the sandbox by manipulating symlinks between the validation and use stages. The synchronous memory tool was not affected.
Recommendations Update to version 0.87.0 or later.

Exploit

Fix

Time Of Check To Time Of Use

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34452
ECHO-38D5-C884-2737
GHSA-W828-4QHX-VXX3
PYSEC-2026-2115

Affected Products

Claude Sdk For Python