Swissky[verified]@pentest_swisskyDisclosure
The article announces research on RCE and API token exfiltration in Claude Code project files, detailing CVE-2025-59536 and CVE-2026-21852.
blackorbird[verified]@blackorbirdDisclosure
The blog post discloses two critical CVEs (CVE-2025-59536 and CVE-2026-21852) in Anthropic’s Claude Code that enable remote code execution and API key theft via malicious repository-level configuration files, triggered simply by cloning and opening an untrusted project.
ゲーミングPC×AI実験室|まっすー[verified]@AIxGamingPCPatch
The tweet lists several CVEs that could leak .env data and API keys, notes that they were supposedly fixed with a version update, and expresses concern about using older versions or unknown vulnerabilities.
Nicolas Krassas[verified]@DinosnDisclosure
The article announces CVE-2025-59536 and CVE-2026-21852, which enable remote code execution and API token exfiltration via Claude code project files.
Sanjeev Kumar[verified]@mishrak_sanjeevGeneral
The article cites AI agent security incidents, including CVE-2026-21852, to highlight authorization best practices, but offers no detailed vulnerability information, PoC, exploit code, or patch guidance.
GoPlus中文社区[verified]@GoPlusZHDisclosure
Check Point Research discloses that Claude Code’s Hooks functionality allows remote code execution and API key theft, and Anthropic has patched the flaw by requiring users to upgrade to version 1.0.111 or newer.
Argus⚒️[verified]@ArgusForgeGeneral
The post notes detection of two CVEs in a deployment but provides no further details on exploitation, patches, or technical specifics.
Carniatto | AI Engineering Labs[verified]@c4rniattoExploit
The post illustrates how CVE-2026-21852 can be exploited via a hidden settings file override to exfiltrate API keys, but no active exploitation or patch information is provided, nor is a PoC or code disclosed.