Claude Code Vulnerabilities

npm AI Tools

Anthropic Claude Code CLI — agentic coding tool AI Threat Alert tracks 19 known vulnerabilities in Claude Code, 1 rated critical — an AI/ML ai tools in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
19
Total CVEs
1
Critical
npm
Ecosystem
Aug 11, 2026
Last CVE
67%
Patch Rate
5d
Avg Time to Patch
142,597 stars 22,840 forks 15,092 issues Last push Aug 23, 2026
View on GitHub

Known Vulnerabilities (17 total, page 1 of 1)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-73222 Claude Code Templates: unauth RCE via shell injection 8.8 Aug 11, 2026 MEDIUM CVE-2026-47751 Claude Code Action: RCE via malicious PR .mcp.json config -- Jul 16, 2026 HIGH CVE-2026-49471 Serena: unauth dashboard API enables RCE via memory poisoning 8.3 Jul 8, 2026 HIGH CVE-2026-55607 Claude Code: worktree bug enables sandbox-escape RCE -- Jun 29, 2026 MEDIUM CVE-2026-46406 Claude Code: predictable temp file leaks data, symlink write -- Jun 25, 2026 HIGH CVE-2026-7574 Claude Desktop: VM integrity bypass enables RCE 8.7 Jun 23, 2026 HIGH CVE-2026-46580 Eclipse Theia: workspace prompt injection enables RCE/exfil -- Jun 18, 2026 HIGH CVE-2026-44688 Eclipse Theia: indirect prompt injection → RCE + exfil -- Jun 18, 2026 MEDIUM CVE-2026-22551 @theia/ai-chat: prompt injection exfiltrates workspace secrets -- Jun 18, 2026 CRITICAL CVE-2026-2611 MLflow: cross-origin bypass enables RCE via AI agent 9.6 May 19, 2026 HIGH CVE-2026-45136 claude-code-cache-fix: hook path injection → RCE -- May 13, 2026 HIGH CVE-2026-44246 nnU-Net: prompt injection hijacks CI/CD triage agent 7.2 May 12, 2026 HIGH CVE-2026-40068 Claude Code: git worktree trust bypass executes hooks -- Apr 24, 2026 HIGH CVE-2026-39861 Claude Code: sandbox escape via symlink allows arbitrary write -- Apr 21, 2026 MEDIUM CVE-2026-35603 Claude Code: config hijack via unprotected ProgramData dir -- Apr 17, 2026 MEDIUM CVE-2026-39398 openclaw-claude-bridge: sandbox bypass exposes CLI tools -- Apr 8, 2026 HIGH CVE-2026-35020 Claude Code CLI: OS command injection via TERMINAL env 8.4 Apr 6, 2026

Frequently asked questions

What is Claude Code?

Anthropic Claude Code CLI — agentic coding tool

How many known vulnerabilities does Claude Code have?

Claude Code has 19 known CVEs, 1 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Claude Code distributed in?

Claude Code is distributed via the npm ecosystem and categorized as ai tools.

Where does the Claude Code vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Claude Code?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Claude Code in your stack

Get instant alerts when new vulnerabilities affect Claude Code. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring