PT-2026-3758 · Anthropic · Claude-Code

·

CVE-2026-21852

·

Published

2026-01-21

·

Updated

2026-08-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 2.0.65
Description A flaw in the project-load flow allows malicious repositories to exfiltrate sensitive data, such as Anthropic API keys, before a user confirms trust in the project. An attacker can include a settings file in a repository that modifies the ANTHROPIC BASE URL variable to point to an attacker-controlled endpoint. When the repository is opened, the software reads this configuration and issues API requests immediately, bypassing the trust prompt and potentially leaking the user's API keys.
Recommendations Update to version 2.0.65 or the latest available version.

Exploit

Fix

RCE

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21852
GHSA-JH7P-QR78-84P7

Affected Products

Claude-Code