Anthropic's vulnerability footprint centers on a narrow portfolio of software development kits and language-model interfaces—Claude SDK variants for Python and TypeScript, Claude Code, and the underlying Claude service—that enable developers to integrate large language models into applications. Though the product count remains modest, the vendor's prominence in the rapidly expanding LLM ecosystem and its role as a foundational dependency across downstream applications place it among more prominent entities in the landscape. Vulnerabilities affecting Anthropic skew strongly toward critical severity and recur through code-execution and path-traversal weakness classes—OS command injection, code injection, path traversal, improper input validation, and symlink following—that reflect the runtime and file-system access inherent to agent-oriented and code-generation features. Defenders integrating these SDKs should treat security advisories as high-priority and audit the execution contexts and file permissions granted to Claude agent deployments. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anthropic over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59536HIGH Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be trick | Oct 3, 2025 | 8.8 | 54 | NO | NO |
CVE-2026-21852HIGH Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthrop | Jan 21, 2026 | 7.5 | 46 | NO | NO |
CVE-2026-55607HIGH Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside th | Jun 29, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-54316CRITICAL Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that d | Jun 23, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-39861CRITICAL Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the w | Apr 21, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-54795CRITICAL Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of | Aug 5, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-64755CRITICAL Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to | Nov 21, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-40068HIGH In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft | May 5, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-25725CRITICAL Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file | Feb 6, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-33068HIGH Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determ | Mar 20, 2026 | 8.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anthropic.
Media articles that mention a CVE ID that affects a product developed by Anthropic — matched by CVE ID, not by vendor name.