Claude Code

Vendor:

First CVE: Aug 5, 2025 · Active for under a year

26
Total CVEs
More Total CVEs than 95% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Claude Code over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2025
11 months ago
Most Recent CVE
Jun 29, 2026
25 days ago

CVE Severity & Scoring

Claude Code26 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (7.7%)
Network24 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (69.2%)
Unknown0 (0.0%)
Required8 (30.8%)
Privileges Required
Low5 (19.2%)
High0 (0.0%)
None21 (80.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be trick
Oct 3, 20258.854NONO
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthrop
Jan 21, 20267.546NONO
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside th
Jun 29, 20268.841NONO
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that d
Jun 23, 20269.136NONO
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the w
Apr 21, 202610.036NONO
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of
Aug 5, 20259.836NONO
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to
Nov 21, 20259.835NONO
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft
May 5, 20268.834NONO
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file
Feb 6, 202610.034NONO
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determ
Mar 20, 20268.833NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Claude Code

Top CWEs

Versions

No cataloged versions.