CVE-2026-44467

HIGH CVSS 4.0: 7.4 EPSS 0.14%
Updated Jun 17, 2026
Anthropic
Parameter Value
CVSS 7.4 (HIGH)
Affected Versions 1.2581.0 — 1.4304.0
Fixed In 1.4304.0
Type CWE-322, CWE-297
Vendor Anthropic
Public PoC No

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development feature verified only whether a hostname existed in ~/.ssh/known_hosts without comparing the server's presented host key against the stored key. This allowed a network-positioned attacker to present an arbitrary SSH host key and have the connection silently accepted, enabling a man-in-the-middle attack on remote development sessions.

Successful exploitation required the attacker to be in a network position to intercept SSH traffic (e.g., via ARP spoofing, rogue Wi-Fi, or DNS poisoning) and the target hostname to already have an entry in the victim's known_hosts file. This vulnerability is fixed in 1.4304.0.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Anthropic Claude_Desktop
cpe:2.3:a:anthropic:claude_desktop:*:*:*:*:*:*:*:*
1.2581.0 1.4304.0