Ad

CVE-2026-21852

MEDIUM CVSS 4.0: 5.3 EPSS 0.02%
Updated Feb 02, 2026
Anthropic
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 2.0.65
Fixed In 2.0.65
Type CWE-522 (Insufficiently Protected Credentials (Недостаточно защищённые учётные данные))
Vendor Anthropic
Public PoC No

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANTHROPIC_BASE_URL to an attacker-controlled endpoint and when the repository was opened, Claude Code would read the configuration and immediately issue API requests before showing the trust prompt, potentially leaking the user's API keys.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.0.65, which contains a patch, or to the latest version.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
None
Права не нужны
User Interaction
Passive
Минимальное взаимодействие

Impact Assessment

Confidentiality
Low
Частичная утечка данных
Integrity
Low
Частичная модификация данных
Availability
Low
Частичное нарушение работы

CVSS Vector v4.0

Vulnerable Products 1

anthropic:claude_code

Known Affected Software Configurations 1

Configuration From (including) Up to (excluding)
Anthropic Claude_Code
cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*
2.0.65