Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks
Anthropic's Claude Code has been identified with critical vulnerabilities, specifically CVE-2025-59536 and CVE-2026-21852, which allow threat actors to exploit repository configuration files. These vulnerabilities enable malicious code execution and…
Anthropic's Claude Code has been identified with critical vulnerabilities, specifically CVE-2025-59536 and CVE-2026-21852, which allow threat actors to exploit repository configuration files. These vulnerabilities enable malicious code execution and unauthorized access to sensitive API keys.
CVE-2025-59536: This vulnerability allows unauthorized action execution by bypassing user consent. It has a CVSS v3.1 score of 8.8 (High) and is exploitable via network attacks with low complexity. CVE-2026-21852: This flaw facilitates API key theft through traffic redirection before trust validation. It is rated 9.1 (Critical) on the CVSS v3.1 scale and can be exploited remotely without user interaction.
Attackers leveraging these vulnerabilities can manipulate Claude Code's project-level configuration files to bypass built-in trust controls. This includes exploiting automation features such as Hooks and Model Context Protocol (MCP) integrations to trigger unauthorized actions when a developer interacts with a malicious repository.
Check Point Research has demonstrated that these vulnerabilities allow silent command execution on a developer's endpoint, even before trust is established. This shifts security control from the user to the repository's configuration, significantly increasing the risk of API credential theft.
These vulnerabilities enable malicious code execution and unauthorized access to sensitive API keys.
In response to these vulnerabilities, Anthropic has implemented several security enhancements:
Strengthened user trust prompts. Blocked execution of external tools without explicit approval. Prevented API communications until trust is confirmed.
These actions address the evolving threat landscape as agentic AI tools become more integrated into enterprise workflows. Organizations are advised to update their security measures to manage the risks associated with AI-driven automation, as repository configuration files now influence execution, networking, and permissions.
Based on reporting by Cyber Security News.
