27 Total advisories
27 Vulnerabilities
0 Malware
Vulnerabilities
UNKNOWN
CVE-2026-46406
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
UNKNOWN
CVE-2026-54316
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
UNKNOWN
CVE-2026-40068
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
CRITICAL 10.0
CVE-2026-39861
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
HIGH 7.3
CVE-2026-35603
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
UNKNOWN
CVE-2026-25724
Claude Code has Permission Deny Bypass Through Symbolic Links
UNKNOWN
CVE-2026-33068
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
UNKNOWN
CVE-2026-25725
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
UNKNOWN
CVE-2026-25723
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
UNKNOWN
CVE-2026-25722
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
UNKNOWN
CVE-2026-24053
Claude Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes
UNKNOWN
CVE-2026-24052
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
UNKNOWN
CVE-2026-24887
Claude Code has a Command Injection in find Command Bypasses User Approval Prompt
UNKNOWN
CVE-2026-21852
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
UNKNOWN
CVE-2025-65099
Claude Code vulnerable to command execution prior to startup trust dialog
UNKNOWN
CVE-2025-59828
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
UNKNOWN
CVE-2025-66032
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
UNKNOWN
CVE-2025-64755
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
UNKNOWN
CVE-2025-59829
Claude Code permission deny bypass through symlink
UNKNOWN
CVE-2025-59536
Claude Code can execute commands prior to the startup trust dialog
UNKNOWN
CVE-2025-59041
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
UNKNOWN
CVE-2025-58764
Claude Code rg vulnerability does not protect against approval prompt bypass
UNKNOWN
GHSA-ph6w-f82w-28w6
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
UNKNOWN
CVE-2025-55284
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
UNKNOWN
CVE-2025-54795
Claude Code echo command allowed bypass of user approval prompt for command execution
UNKNOWN
CVE-2025-54794
Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
UNKNOWN
CVE-2025-52882
Claude Code Improper Authorization via websocket connections from arbitrary origins
Ready to move
Start Securing
Free, no credit card | First findings in minutes