Junglewise Threat Intelligence

CVE-2026-44467: Anthropic Claude Desktop SSH host key verification bypass

CVE-2026-44467 · Severity: medium · CVSS 6.8 · Published 2026-05-13

Technologies: Anthropic Claude Desktop. Vendors: Anthropic.

Executive brief

Claude Desktop is an application used for AI-assisted coding and remote development. A security flaw in its SSH feature allowed attackers on the same local network to intercept and modify remote development sessions. This could lead to the theft of sensitive code or the injection of malicious commands into the developer's environment.

Technical details

Claude Desktop's SSH remote development feature (versions 1.2581.0 to 1.4304.0) improperly validated server identities. While the application checked if a hostname existed in the user's known_hosts file, it failed to compare the server's presented host key against the stored key. An attacker positioned on the local network (e.g., via ARP spoofing or rogue Wi-Fi) could present an arbitrary SSH host key, which the application would silently accept. This allows for a Man-in-the-Middle (MitM) attack, granting the attacker the ability to intercept or modify traffic within the SSH session. The vulnerability is resolved in version 1.4304.0.

Affected products

  • Anthropic Claude Desktop from 1.2581.0 before 1.4304.0

Timeline

  • 2026-05-06: advisory: Vendor advisory published on GitHub
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats