Claude Code
Vendor:
First CVE: Aug 5, 2025 · Active for under a year
26
Total CVEs
More Total CVEs than 95% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Claude Code over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2025
11 months ago
Most Recent CVE
Jun 29, 2026
25 days ago
CVE Severity & Scoring
Claude Code26 CVEs
15%
38%
46%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.7%)
Network24 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (69.2%)
Unknown0 (0.0%)
Required8 (30.8%)
Privileges Required
Low5 (19.2%)
High0 (0.0%)
None21 (80.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59536HIGH Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be trick | Oct 3, 2025 | 8.8 | 54 | NO | NO |
CVE-2026-21852HIGH Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthrop | Jan 21, 2026 | 7.5 | 46 | NO | NO |
CVE-2026-55607HIGH Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside th | Jun 29, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-54316CRITICAL Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that d | Jun 23, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-39861CRITICAL Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the w | Apr 21, 2026 | 10.0 | 36 | NO | NO |
CVE-2025-54795CRITICAL Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of | Aug 5, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-64755CRITICAL Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to | Nov 21, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-40068HIGH In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft | May 5, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-25725CRITICAL Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file | Feb 6, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-33068HIGH Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determ | Mar 20, 2026 | 8.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Claude Code
Top CWEs
Versions
No cataloged versions.