Skip to main content

CVE detail

CVE-2026-21852

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANTHROPIC_BASE_URL to an attacker-controlled endpoint and when the repository was opened, Claude Code would read the configuration and immediately issue API requests before showing the trust prompt, potentially leaking the user's API keys. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.0.65, which contains a patch, or to the latest version.

CVSS 5.3 · MediumBuzz score 41.51 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 41.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 4.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
18.0
5 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
4.0
1 repos · best confidence 0.80
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • rganizational artificial intelligence (AI) infrastructure. Researchers from Wiz Research discovered the bug, tracked as CVE-2026-12957 , in the Amazon Q Developer extension for Visual Studio Code, according to a recent blog post . The flaw stemmed from Amazon Q's handling of MCP, which by default automatically loaded and executed MCP server configurati

    newswww.darkreading.comJun 29, 2026, 11:44 AM
  • Claude Code is Anthropic’s AI coding assistant — a command-line tool that developers are adopting fast. It connects to external services through Model Context Protocol, the standard that lets AI tools interact with Jira, Confluence, GitHub, databases and internal APIs. When a developer connects one of those services, Claude Code runs an OAuth flow, the […]

    newswww.csoonline.comJun 5, 2026, 9:00 AM
  • AI Threat Landscape Digest March-April 2026Check Point Research

    earchers identified an exposed operator server. Bissa is a modular mass-exploitation platform built around React2Shell (CVE-2025-55182), with 900+ confirmed compromises across millions of scanned Next.js endpoints and an archive of 30,000+ distinct .env filenames recovered from operator-controlled S3 storage. The operation has been running since Septem

    vendorresearch.checkpoint.comMay 26, 2026, 10:09 AM
  • Flaws in Anthropic’s Claude Code could allow remote code execution and theft of API keys when users open untrusted repositories. Check Point Research team found multiple vulnerabilities in Anthropic’s Claude Code AI coding assistant that could lead to remote code execution and API key theft. The vulnerabilities abuse features such as Hooks, MCP servers, and […]

    newssecurityaffairs.comFeb 25, 2026, 9:39 PM
  • By Aviv Donenfeld and Oded Vanunu Executive Summary Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various configuration mechanisms including Hooks, Model Context Protocol (MCP) servers, and environment variables -executing arbitrary shell commands […]

    vendorresearch.checkpoint.comFeb 25, 2026, 1:58 PM
  • No excerpt available.

    Exploitgithub.comJan 21, 2026, 9:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.80 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-52855

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates…

    CVSS 9.9 · Critical
    3 mentions
  • CVE-2026-56570

    HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account iden…

    CVSS 3.7 · Low
    1 mention
  • CVE-2026-17349

    /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(),…

    CVSS 9.3 · Critical
    3 mentions
  • CVE-2026-15977

    SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

    CVSS 7.5 · High
    2 mentions
  • CVE-2026-15657

    A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

    CVSS 6.5 · Medium
    1 mention
  • CVE-2026-16553

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have all…

    CVSS 5.4 · Medium
    2 mentions