Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Anthropic

First CVE: Aug 5, 2025Active for: 1 yearTotal CVEs: 33
52.0
VTI Score
TOP TARGET

Anthropic's vulnerability footprint centers on a narrow portfolio of software development kits and language-model interfaces—Claude SDK variants for Python and TypeScript, Claude Code, and the underlying Claude service—that enable developers to integrate large language models into applications. Though the product count remains modest, the vendor's prominence in the rapidly expanding LLM ecosystem and its role as a foundational dependency across downstream applications place it among more prominent entities in the landscape. Vulnerabilities affecting Anthropic skew strongly toward critical severity and recur through code-execution and path-traversal weakness classes—OS command injection, code injection, path traversal, improper input validation, and symlink following—that reflect the runtime and file-system access inherent to agent-oriented and code-generation features. Defenders integrating these SDKs should treat security advisories as high-priority and audit the execution contexts and file permissions granted to Claude agent deployments. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Anthropic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2025
11 months ago
Most Recent CVE
Jun 29, 2026
25 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-59536HIGH
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be trick
Oct 3, 20258.854NONO
CVE-2026-21852HIGH
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthrop
Jan 21, 20267.546NONO
CVE-2026-55607HIGH
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside th
Jun 29, 20268.841NONO
CVE-2026-54316CRITICAL
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that d
Jun 23, 20269.136NONO
CVE-2026-39861CRITICAL
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the w
Apr 21, 202610.036NONO
CVE-2025-54795CRITICAL
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of
Aug 5, 20259.836NONO
CVE-2025-64755CRITICAL
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to
Nov 21, 20259.835NONO
CVE-2026-40068HIGH
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft
May 5, 20268.834NONO
CVE-2026-25725CRITICAL
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file
Feb 6, 202610.034NONO
CVE-2026-33068HIGH
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determ
Mar 20, 20268.833NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
27%
36%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (21.2%)
Network25 (75.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.0%)
Attack Complexity
Low30 (90.9%)
High3 (9.1%)
Unknown0 (0.0%)
User Interaction
None24 (72.7%)
Unknown0 (0.0%)
Required9 (27.3%)
Privileges Required
Low9 (27.3%)
High0 (0.0%)
None24 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Anthropic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Anthropic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Anthropic's Products

View all 2 CNAs →

Top CWEs