Technology · Anthropic
Anthropic Claude Code vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Anthropic Claude Code: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55607, was published on 29 June 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
Latest Anthropic Claude Code vulnerabilities
- CVE-2026-55607: Anthropic Claude Code sandbox escape via git worktree path confusionhighCVSS 4EPSS 0.7%
- CVE-2026-46406: Anthropic Claude Code insecure temporary file in copy commandmediumCVSS 4EPSS 0.1%
- CVE-2026-54316: Anthropic Claude Code data exfiltration via HuggingFace allowlist bypassmediumCVSS 3.1EPSS 0.5%
- CVE-2026-40068: Anthropic Claude Code trust bypass via Git worktree spoofinghighCVSS 8.8EPSS 0.6%
- CVE-2026-39861: Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspacecriticalCVSS 10EPSS 0.8%
- CVE-2026-35603: Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowshighCVSS 7.3EPSS 0.1%
- CVE-2026-33068: Anthropic Claude Code workspace trust dialog bypass via settings filemediumCVSS 4EPSS 0.6%
- CVE-2026-25725: Anthropic Claude Code sandbox escape via configuration injectionmediumCVSS 4EPSS 0.6%
- CVE-2026-25724: Claude Code permission bypass through symbolic linksmediumCVSS 4EPSS 0.6%
- CVE-2026-25723: Anthropic Claude Code command injection via piped sedmediumCVSS 4EPSS 0.5%
- CVE-2026-25722: Anthropic Claude Code command injection via directory traversalmediumCVSS 4EPSS 0.6%
- CVE-2026-24887: Anthropic Claude Code command injection in find commandmediumCVSS 4EPSS 0.6%
- CVE-2026-24053: Anthropic Claude Code path restriction bypass via ZSH clobbermediumCVSS 4EPSS 0.5%
- CVE-2026-24052: Anthropic Claude Code domain validation bypass in WebFetchmediumCVSS 4EPSS 0.4%
- CVE-2026-21852: Anthropic Claude Code credential leakage via malicious environment configurationmediumCVSS 4EPSS 27.9%
- CVE-2025-66032: Anthropic Claude Code command validation bypassmediumCVSS 4EPSS 0.7%
- CVE-2025-64755: Anthropic claude-code sed command validation bypassmediumCVSS 4EPSS 0.5%
- CVE-2025-65099: Anthropic Claude Code command execution prior to trust dialogmediumCVSS 4EPSS 0.5%
- CVE-2025-59829: Anthropic Claude Code permission bypass via symlinkmediumCVSS 4EPSS 0.4%
- CVE-2025-59536: Anthropic Claude Code command execution before trust dialogmediumCVSS 4EPSS 27.2%
- CVE-2025-59828: Anthropic Claude Code arbitrary code execution via Yarn plugin autoloadingmediumCVSS 4
- CVE-2025-59041: Anthropic Claude Code arbitrary code execution in git configurationmediumCVSS 4EPSS 0.5%
- CVE-2025-58764: Anthropic Claude Code rg command injection approval bypassmediumCVSS 4EPSS 0.5%
- Anthropic Claude Code arbitrary code execution via insufficient startup warningmediumCVSS 4
- CVE-2025-55284: Anthropic Claude Code permissive allowlist enables file read and network exfiltrationmediumCVSS 4EPSS 0.5%
Most severe Anthropic Claude Code vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-39861: Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspacecriticalCVSS 10EPSS 0.8%
- CVE-2026-40068: Anthropic Claude Code trust bypass via Git worktree spoofinghighCVSS 8.8EPSS 0.6%
- CVE-2026-35603: Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowshighCVSS 7.3EPSS 0.1%
- CVE-2026-55607: Anthropic Claude Code sandbox escape via git worktree path confusionhighCVSS 4EPSS 0.7%
- CVE-2026-21852: Anthropic Claude Code credential leakage via malicious environment configurationmediumCVSS 4EPSS 27.9%
- CVE-2025-59536: Anthropic Claude Code command execution before trust dialogmediumCVSS 4EPSS 27.2%
- CVE-2025-54794: Anthropic Claude Code path restriction bypassmediumCVSS 4EPSS 1.4%
- CVE-2025-54795: Anthropic Claude Code echo command injection bypass of user approval promptmediumCVSS 4EPSS 1.0%
- CVE-2025-66032: Anthropic Claude Code command validation bypassmediumCVSS 4EPSS 0.7%
- CVE-2026-25725: Anthropic Claude Code sandbox escape via configuration injectionmediumCVSS 4EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/claude-code.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Anthropic Claude Code vulnerabilities", https://junglewise.ai/threats/technologies/claude-code, 26 September 2026.