Junglewise Threat Intelligence

CVE-2026-35022: Anthropic Claude Code OS command injection in authentication helpers

CVE-2026-35022 · Severity: info · CVSS 9.8 · Published 2026-04-06

Technologies: Anthropic Claude Code CLI, Anthropic Claude Agent SDK. Vendors: Anthropic.

Executive brief

Anthropic's Claude Code CLI and Agent SDK are tools used by developers to integrate AI capabilities into their software and workflows. A vulnerability in how these tools handle authentication settings could allow an attacker to execute unauthorized commands on a user's system. This could lead to the theft of sensitive credentials, exposure of environment variables, and full compromise of the development or automation environment. Note: This vulnerability was later disputed and rejected by the CNA, as the behavior is considered documented functionality when used in untrusted directories.

Technical details

The Anthropic Claude Code CLI (up to 2.1.91) and Claude Agent SDK (up to 0.1.55) are susceptible to OS command injection (CWE-78). The root cause is the use of 'shell=true' during the execution of authentication helper configuration values without sufficient input validation. An attacker who can influence authentication settings—specifically parameters like apiKeyHelper, awsAuthRefresh, awsCredentialExport, and gcpAuthRefresh—can inject shell metacharacters. This allows for arbitrary command execution with the privileges of the current user or the automation environment. Although initially assigned a high CVSS score, the CVE was subsequently rejected by the CNA because the behavior is documented in the help output, which warns that non-interactive mode should only be used in trusted directories.

Affected products

  • Anthropic Claude Code CLI up to 2.1.91
  • Anthropic Claude Agent SDK up to 0.1.55

Timeline

  • 2026-04-06: disclosed: Initial vulnerability report published by VulnCheck.
  • 2026-04-13: other: Vulnerability marked as disputed.
  • 2026-05-29: other: CVE rejected by the CNA.

Related threats