CVE-2025-59536Disclosure(anthropic / claude_code)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch anthropic claude_code systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 101 mentions across 47 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 73 signals
  • Disclosure: 42 classified signals
  • General: 26 classified signals
  • Peaked 45d ago at 17 mentions (2026-02-26); latest day: 1
  • 101 total mentions across 47 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline101 mentions / 47d
0491317Mentions · 2026-02-25: 7Mentions · 2026-02-26: 17Mentions · 2026-02-27: 12Mentions · 2026-02-28: 3Mentions · 2026-03-01: 4Mentions · 2026-03-02: 5Mentions · 2026-03-03: 2Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-16: 1Mentions · 2026-03-17: 3Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-24: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-07: 2Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-10: 4Mentions · 2026-05-23: 1Mentions · 2026-05-28: 1Mentions · 2026-06-10: 1Mentions · 2026-06-19: 1Mentions · 2026-06-27: 1Mentions · 2026-09-21: 1Mentions · 2026-09-23: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-02-26: 2PoC Mentioned / Linked · 2026-02-27: 2PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-14: 1Exploit Tool / Code · 2026-02-26: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-05-10: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-02-26: 4Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-28: 1Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-02-26: 4Patch / Workaround · 2026-02-27: 5Patch / Workaround · 2026-02-28: 2Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-09-21: 1Technical Details · 2026-02-25: 7Technical Details · 2026-02-26: 11Technical Details · 2026-02-27: 10Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-24: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 3Technical Details · 2026-05-28: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-19: 1Technical Details · 2026-09-21: 1Technical Details · 2026-09-23: 102-2503-0103-0803-1703-2704-0204-0904-2204-2805-0705-2809-2109-24
Signal classification6 categories
Disclosure
4241.6%
General
2625.7%
Patch
2019.8%
Active Exploitation
87.9%
PoC
33.0%
Exploit
22.0%
Referenced assets68 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-257
Disclosure5Patch2
2026-02-2617
Active Exploitation3Disclosure5General4Patch4PoC1
2026-02-2712
Disclosure7General3Patch2
2026-02-283
General1Patch2
2026-03-014
Disclosure1General3
2026-03-025
Disclosure2General3
2026-03-032
Active Exploitation1Disclosure1
2026-03-051
PoC1
2026-03-081
General1
2026-03-091
General1
2026-03-102
Disclosure1Patch1
2026-03-161
Patch1
2026-03-173
Active Exploitation1Disclosure1General1
2026-03-181
Disclosure1
2026-03-192
Disclosure1Patch1
2026-03-242
Disclosure2
2026-03-271
Disclosure1
2026-03-281
General1
2026-03-301
General1
2026-03-312
Patch1PoC1
2026-04-021
Disclosure1
2026-04-031
Disclosure1
2026-04-072
Disclosure1Exploit1
2026-04-082
Disclosure1General1
2026-04-091
Active Exploitation1
2026-04-111
Disclosure1
2026-04-141
Patch1
2026-04-191
General1
2026-04-221
Disclosure1
2026-04-231
General1
2026-04-241
General1
2026-04-261
Patch1
2026-04-281
General1
2026-04-301
Disclosure1
2026-05-011
Patch1
2026-05-041
Patch1
2026-05-071
Active Exploitation1
2026-05-081
Disclosure1
2026-05-104
Disclosure3Exploit1
2026-05-231
Patch1
2026-05-281
Active Exploitation1
2026-06-101
General1
2026-06-191
Disclosure1
2026-06-271
General1
2026-09-211
Patch1
2026-09-231
Disclosure1
2026-09-241
Disclosure1
Full discourse20 posts
  • Oded Vanunu@Od3dV
    Active Exploitation

    I hacked Claude Code! It turns out "agentic" is just a fancy new way to get a shell. I achieved full RCE and hijacked organization API keys. CVE-2025-59536 | CVE-2026-21852 https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/ #ai #Claude

    Post summary

    The author claims to have exploited CVE-2025-59536 and CVE-2026-21852, achieving full remote code execution and API key hijacking, but no PoC, patch, or detailed exploit code is provided.

    1112718591431103.4K
    599 followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Disclosure

    RCE AND API TOKEN EXFILTRATION THROUGH CLAUDE CODE PROJECT FILES https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    Checkpoint research discloses CVE-2025-59536, a vulnerability that permits remote code execution and API token exfiltration via Claude code project files.

    0270115847.3K
    77.2K followersView on X
  • Het Mehta@hetmehtaa
    Disclosure

    RCE AND API TOKEN EXFILTRATION THROUGH CLAUDE CODE PROJECT FILES https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    The article announces a new CVE (2025-59536) that enables remote code execution and API token exfiltration via Claude code project files.

    214058313.2K
    39.4K followersView on X
  • Swissky@pentest_swissky
    Disclosure

    Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852 - Aviv Donenfeld and Oded Vanunu https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    Checkpoint researchers disclose two new CVEs (2025-59536 and 2026-21852) involving remote code execution and API token exfiltration via Claude code project files.

    08023192.4K
    21.7K followersView on X
  • blackorbird@blackorbird
    Disclosure

    Critical vulnerabilities, CVE-2025-59536 and CVE-2026-21852, in Anthropic’s Claude Code enabled remote code execution and API key theft through malicious repository-level configuration files, triggered simply by cloning and opening an untrusted project https://blog.checkpoint.com/research/check-point-researchers-expose-critical-claude-code-flaws/ https://t.co/seoIHfG9Iu

    Post summary

    The blog post discloses two critical CVEs (CVE-2025-59536 and CVE-2026-21852) in Anthropic’s Claude Code that enable remote code execution and API key theft via malicious repository-level configuration files, triggered simply by cloning an untrusted project.

    0802592.4K
    40.1K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Check Point found CVE-2025-59536 and CVE-2026-21852 in Claude Code allow remote code execution and API key theft via untrusted repository configurations, reachable by simply cloning and opening a project. They warn that built-in hooks and env vars could … https://blog.checkpoint.com/research/check-point-researchers-expose-critical-claude-code-flaws/

    Post summary

    Check Point researchers identified two CVEs in Claude Code that enable remote code execution and API key theft through untrusted repository configurations, exploitable simply by cloning a project.

    21201511.0K
    21.3K followersView on X
  • kαι@roguekode
    Disclosure

    Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    The linked research article discloses CVE‑2025‑59536, a vulnerability that allows remote code execution and exfiltration of API tokens via Claude code project files.

    0301771.3K
    16.6K followersView on X
  • Total Cyber-Sec@totalcybersec
    Disclosure

    #Cybernews 🚨💻 Las #Vulnerabilidades ⚠️, registradas como CVE-2025-59536 🆔 y CVE-2026-21852 🆔, podían activarse simplemente al #Clonar 🔁 y abrir 📂 un proyecto no confiable 🚫, sin necesidad de ejecutar código explícito 🧩 ni realizar acciones adicionales. https://t.co/C4zqm9ukAG

    Post summary

    The tweet announces two CVEs that can be triggered by simply cloning and opening a project, without executing additional code.

    12060301
    15.9K followersView on X
  • @bluecow 🐮@BLUECOW009
    Disclosure

    Researchers have a clear path to hack with claude code: >get user to install skill >skill setup hooks >hooks get executed without asking user permission >hooks can download and run binaries https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/ https://t.co/xQKnWSZqUh

    Post summary

    Researchers disclosed a Remote Code Execution vulnerability (CVE-2025-59536) in Claude code project files that allows installation of skills, hook execution without permission, and binary execution, potentially exfiltrating API tokens. No PoC, exploit tool, active exploitation evidence, or patch information is provided.

    00045415
    19.1K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852 https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    Checkpoint research highlights RCE and API token exfiltration vulnerabilities in Claude code project files (CVE-2025-59536 and CVE-2026-21852).

    020241.5K
    151.6K followersView on X
  • Permission Protocol@PermissionPrtcl
    General

    Recent #ClaudeCode vulnerabilities (CVE-2025-59536, CVE-2026-21852) show why the AI supply chain begins with the automation layer. Configuration files like .claude/settings.json are now part of the execution layer. Authority must be deterministic. 🛡️🦾 https://thehackernews.com/2026/02/claude-code-flaws-allow-remote-code.html

    Post summary

    The tweet references two ClaudeCode CVEs but does not provide PoC details, exploit code, proof of active exploitation, or patch information.

    10050152
    35 followersView on X
  • GoPlus中文社区@GoPlusZH
    Patch

    ⚠️Check Point Research(CPR)发布报告详细揭示 #Claude Code 存在通过项目文件实现远程代码执行和 API 令牌窃取等多个严重漏洞(CVE-2025-59536 和相关 CVE-2026-21852)。 该漏洞并非源于传统的代码注入,而是由于 Claude Code 在处理项目级配置文件时,其自动化功能与安全信任机制之间的逻辑缺陷: 1、Hooks(钩子)功能滥用:Claude Code 支持“Hooks”功能,攻击者在仓库的 .claude/settings.json 文件中定义恶意 Hook 命令。当用户在该目录下运行 claude 命令时,这些脚本会在后台自动启动。 2、信任机制绕过(Execution Before Trust):恶意配置定义的命令执行时间点早于信任提示的出现。这意味着即使你在看到提示后选择了“不信任”并退出,恶意代码可能已经执行完毕(例如弹出了计算器或发送了数据)。 3、MCP劫持:Claude Code 使用 MCP 与外部工具交互。攻击者通过伪造 .mcp.json 配置文件,可以静默地将原本安全的本地工具替换为恶意可执行文件。 4、API 令牌脱出(Exfiltration via Base URL):当 Claude Code 进行身份验证时,它会将用户的 Authorization 请求头(包含 Anthropic API Key)发送到攻击者的服务器。整个过程发生在用户确认信任该目录之前。 🛡️目前 #Anthropic 已经修复了上述漏洞,开发者需升级到版本在 1.0.111 以上,避免此漏洞;另外,避免在不可信的第三方仓库或不明来源的目录下运行 claude 等 AI 命令行工具。

    Post summary

    The report details new remote code execution and API key exfiltration flaws in Claude Code; Anthropic has released a patch, and users should upgrade to v1.0.111 or later and avoid running Claude from untrusted directories.

    01032745
    6.4K followersView on X
  • 週末ものづくり部@shumatsumonobu
    Patch

    Claude Codeに脆弱性。攻撃者がリポに.claude/settings.jsonをコミットしておくだけ。cloneして開いたらAPIキーが外に飛ぶ。修正済み。設定ファイルはノーマークだった。.claude/があるリポ、中身見てから開く https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

    Post summary

    CVE‑2025‑59536 in Claude Code allows exfiltration of API keys via a committed .claude/settings.json file; the issue is reported as fixed, but no detailed patch information is provided.

    00050259
    141 followersView on X
  • jiayun@jiayun
    Disclosure

    🚀 Top 10 AI & Dev News of the Day! 🧵👇 🚨 Claude Code RCE Flaws: Check Point Research discovered critical vulnerabilities (like CVE-2025-59536) in Claude Code that allow remote code execution and API key theft simply by opening malicious repositories. https://www.bankinfosecurity.com/malicious-repo-files-could-hijack-claude-code-sessions-a-30854 ⚠️ Gemini API Data Leaks: Legacy public Google Cloud API keys (like Maps or Firebase) are silently inheriting unauthorized access to Gemini endpoints, exposing private files and creating massive billing risks. https://ift.tt/JiALlab ⚔️ Anthropic Defies the Pentagon: CEO Dario Amodei publicly rejected the DoD's ultimatum, refusing to drop Claude's safety guardrails against autonomous lethal weapons and mass domestic surveillance. https://ift.tt/hL2AqHi 🐛 MCP Go SDK Vulnerability: Upgrade to v1.3.1 immediately! A high-severity flaw (CVE-2026-27896) allows attackers to bypass security filters due to case-insensitive JSON parsing. https://ift.tt/0QNCImq 📱 Claude Code Remote Control: Anthropic launched a highly-requested feature letting developers seamlessly control and monitor their local terminal coding sessions directly from their phones. https://ift.tt/u3OLgIP 🤖 Microsoft Copilot Tasks: Microsoft unveiled an autonomous background agent that plans and executes multi-step workflows (like calendar management or web research) across different apps without constant human input. https://ift.tt/SdL6NjA 🤝 Copilot Welcomes Claude & Codex: GitHub Copilot Pro and Business users can now select Anthropic's Claude and OpenAI's Codex as their coding agents directly inside VS Code at no extra cost. https://ift.tt/C8WUYGR 🛡️ MCP Server Security Audit: An independent scan of the top 20 Model Context Protocol (MCP) servers revealed that 60% contain real vulnerabilities, including critical arbitrary command execution flaws in Kubernetes servers. https://ift.tt/WrzYOle 🎨 Figma integrates OpenAI Codex: Figma launched a new workflow via its MCP server that connects its infinite design canvas directly to Codex, allowing teams to seamlessly translate UI designs into code. https://ift.tt/I3MuOlk 🖼️ Google's Nano Banana 2: Google shipped Gemini 3.1 Flash Image, crushing the competition by taking the #1 spot on text-to-image leaderboards while costing half the price of Pro models. https://www.latent.space/p/ainews-nano-banana-2-aka-gemini-31 #AI #MachineLearning #CyberSecurity #SoftwareDevelopment #TechNews #WebDev #OpenAI #Anthropic #GitHubCopilot

    Post summary

    The post announces newly discovered critical vulnerabilities in Claude Code and MCP Go SDK, highlighting remote code execution and filter bypass risks, and urges immediate patching for the MCP vulnerability.

    01031166
    199 followersView on X
  • Stephan Ferraro@StephanFerraro
    General

    The Claude Code RCE vulnerability (CVE-2025-59536) is a perfect case study for why agentic AI needs security-first architecture. Giving AI agents shell access without proper sandboxing is like handing out root keys to your infrastructure. Every team deploying coding agents should audit their trust boundaries now.

    Post summary

    The post discusses CVE‑2025‑59536 as a shell-access RCE risk for AI agents and urges teams to review trust boundaries, but it provides no technical exploit details, patches, or evidence of active use.

    2002184
    259 followersView on X
  • Adarsh Singh@adarshk27r
    Disclosure

    ⚠️ "Vibe coding" is the new buzzword for 2026. But nobody is talking about the massive security timebomb it just created. Just weeks ago, Check Point Research exposed a critical vulnerability (CVE-2025-59536) in Anthropic’s Claude Code. Right now, founders are pushing development teams to let AI agents run loose in their codebases to speed up deployment. But attackers realized they could hide malicious hooks inside simple project files (like .claude/settings.json). The moment a developer clones an untrusted repository and activates the AI agent, it triggers Remote Code Execution (RCE) and quietly exfiltrates enterprise API keys. 🔑 This highlights the biggest trap in the current AI hype cycle: treating AI as a magic wrapper instead of a core engineering component. 🛡️ Whether I am deploying enterprise Node.js architectures or designing platforms for secure digital asset distribution, the rule remains the same: you cannot have autonomy without strict boundaries. AI agents are incredible engines. But if you don't have the fundamental engineering architecture to sandbox them, validate their outputs, and control their access, you aren't automating your business; you are automating your breaches. 📦 We need to stop chasing the hype of "zero-click" development and start focusing on secure, containerized AI integration. Founders, CTOs, and fellow engineers: How are you currently sandboxing AI agents within your local development environments to prevent automated credential leaks? 👇 I’d love to hear the different architectural approaches you are taking.

    Post summary

    Check Point Research has exposed a critical RCE flaw (CVE-2025-59536) in Anthropic’s Claude Code that can be triggered via malicious .claude/settings.json files, allowing attackers to exfiltrate API keys.

    20020188
    18 followersView on X
  • Argus⚒️@ArgusForge
    General

    Running a 5-bot Claude Code swarm on political data. Built the same progressive disclosure pattern independently for auto-capturing human corrections and prepending them to agent prompts. Context rot solved with a 150-line cap and 30-day expiry. Also caught CVE-2025-59536 and CVE-2026-21852 in our deployment within 48 hours. Scaffold security is the real frontier. Great post. Validates a lot of hard-won lessons!

    Post summary

    The post notes that two CVEs were detected in the author’s deployment but provides no further technical or exploit details.

    00040185
    3.4K followersView on X
  • Justin Kwon@ju571nK
    Patch

    AIコーディングエージェントが攻撃される本当の入口は、モデルではなく「設定ファイル」でした。 TrustFall・AWS Kiro・CVE-2025-59536 を題材に整理して、対策に作ったツール Sigil も紹介しています。|Justin https://zenn.dev/ju571n/articles/ai-agent-config-attack-surface #zenn

    Post summary

    The post highlights that the real entry point for attacks on an AI coding agent is in configuration files, references CVE-2025-59536, and introduces a mitigation tool named Sigil, yet it offers no PoC, exploit, or detailed vulnerability data.

    10020745
    6 followersView on X
  • AI駆動開発ラボ@aidriven1234
    Patch

    悪意あるリポジトリをクローンするだけでRCEとAPIキー窃取が起きるClaude Code脆弱性(CVE-2025-59536/CVE-2026-21852)が発見・修正済み。根本原因は.claude/settings.jsonがリポジトリ内に存在すること。信頼できないリポジトリを開く前にこのファイルを必ず確認する運用が必要。 #AIコーディング

    Post summary

    The post announces the discovery and patching of CVE-2025-59536/CVE-2026-21852, explains the root cause, and recommends a pre-check to mitigate potential RCE and API key theft.

    10020723
    53 followersView on X
  • 0xAlphaAI@0xAlpha
    General

    @MindTheGapMTG @gregisenberg Both layers leak. My honeymcp catches payloads abusing MCP tool authorization (write_file to .mcp.json hooks, CVE-2025-59536 class) alongside classic injection. You need runtime permissions AND input detection. Skip one, attacker walks through the gap.

    Post summary

    The tweet indicates that both layers can be exploited via the MCP tool’s write_file hook (CVE‑2025‑59536) and underscores the need for runtime permissions and input detection, but provides no PoC, active exploitation data, or patch information.

    10011269
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more