H4x0r.DZ 🇰🇵[verified]@h4x0r_dzDisclosure
Checkpoint research discloses CVE-2025-59536, a vulnerability that permits remote code execution and API token exfiltration via Claude code project files.
Het Mehta[verified]@hetmehtaaDisclosure
The article announces a new CVE (2025-59536) that enables remote code execution and API token exfiltration via Claude code project files.
Swissky[verified]@pentest_swisskyDisclosure
Checkpoint researchers disclose two new CVEs (2025-59536 and 2026-21852) involving remote code execution and API token exfiltration via Claude code project files.
blackorbird[verified]@blackorbirdDisclosure
The blog post discloses two critical CVEs (CVE-2025-59536 and CVE-2026-21852) in Anthropic’s Claude Code that enable remote code execution and API key theft via malicious repository-level configuration files, triggered simply by cloning an untrusted project.
@bluecow 🐮[verified]@BLUECOW009Disclosure
Researchers disclosed a Remote Code Execution vulnerability (CVE-2025-59536) in Claude code project files that allows installation of skills, hook execution without permission, and binary execution, potentially exfiltrating API tokens. No PoC, exploit tool, active exploitation evidence, or patch information is provided.
Nicolas Krassas[verified]@DinosnDisclosure
Checkpoint research highlights RCE and API token exfiltration vulnerabilities in Claude code project files (CVE-2025-59536 and CVE-2026-21852).
GoPlus中文社区[verified]@GoPlusZHPatch
The report details new remote code execution and API key exfiltration flaws in Claude Code; Anthropic has released a patch, and users should upgrade to v1.0.111 or later and avoid running Claude from untrusted directories.
jiayun[verified]@jiayunDisclosure
The post announces newly discovered critical vulnerabilities in Claude Code and MCP Go SDK, highlighting remote code execution and filter bypass risks, and urges immediate patching for the MCP vulnerability.