@anthropic-ai/claude-code
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @anthropic-ai/claude-codepage 1 of 1
- CVE-2025-52882HIGHCVSS 8.8EG 0.0✓ Fixed in 1.0.242025-06-24
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections …
- CVE-2026-24053MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.0.742026-02-03
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory wit…
- CVE-2026-25724HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1.72026-02-06
Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a f…
- CVE-2026-25725CRITICALCVSS 10.0EG 10.0✓ Fixed in 2.1.22026-02-06
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directo…
- CVE-2026-35603HIGHCVSS 7.3EG 7.3✓ Fixed in 2.1.752026-04-17
Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access p…
- CVE-2026-39861CRITICALCVSS 10.0EG 10.0✓ Fixed in 2.1.642026-04-21
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path wit…
- CVE-2026-40068HIGHCVSS 8.8EG 8.8✓ Fixed in 2.1.842026-05-05
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a…
Check whether @anthropic-ai/claude-code is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @anthropic-ai/claude-code CVEs against the assets you own.
Start Free Scan →