CVE-2026-21852 is a critical vulnerability affecting Anthropic's Claude Code prior to version 2.0.65. It allowed malicious repositories to exfiltrate sensitive data, specifically Anthropic API keys, before a user could even confirm trust in the project. An attacker could configure a repository to redirect API requests to an attacker-controlled endpoint, leading to immediate API key leakage upon opening the project. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction to exploit. The primary impact is a complete compromise of confidentiality (C:H) due to the exfiltration of API keys. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 19 mentions across various platforms and media coverage, indicating a high level of awareness and concern. Users on standard auto-update have received the fix, and manual update users are advised to upgrade to version 2.0.65 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.65CPE matchmatch criteria | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.