PT-2026-3758 · Anthropic · Claude-Code
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Claude Code versions prior to 2.0.65
Description
A flaw in the project-load flow allows malicious repositories to exfiltrate sensitive data, such as Anthropic API keys, before a user confirms trust in the project. An attacker can include a settings file in a repository that modifies the
ANTHROPIC BASE URL variable to point to an attacker-controlled endpoint. When the repository is opened, the software reads this configuration and issues API requests immediately, bypassing the trust prompt and potentially leaking the user's API keys.Recommendations
Update to version 2.0.65 or the latest available version.
Exploit
Fix
RCE
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Claude-Code