CVE-2026-25725Disclosure(anthropic / claude_code)

HIGHCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch anthropic claude_code systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was mounted as writable and .claude/settings.local.json was explicitly protected with read-only constraints, settings.json was not protected if it was missing. This allowed malicious code running inside the sandbox to create this file and inject persistent hooks (such as SessionStart commands) that would execute with host privileges when Claude Code was restarted. This issue has been patched in version 2.1.2.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-501CWE-668

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 2 mentions (2026-02-06); latest day: 1
  • 12 total mentions across 8 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline12 mentions / 8d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 2Mentions · 2026-04-08: 2Mentions · 2026-06-26: 1Mentions · 2026-07-28: 1Mentions · 2026-08-19: 1Exploit Tool / Code · 2026-06-26: 1Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-04-08: 2Technical Details · 2026-06-26: 1Technical Details · 2026-07-28: 1Technical Details · 2026-08-19: 102-0602-0902-1002-1104-0806-2607-2808-19
Signal classification4 categories
Disclosure
866.7%
General
216.7%
Patch
18.3%
Active Exploitation
18.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-091
Disclosure1
2026-02-102
Disclosure1General1
2026-02-112
Disclosure1General1
2026-04-082
Disclosure1Patch1
2026-06-261
Disclosure1
2026-07-281
Active Exploitation1
2026-08-191
Disclosure1
Full discourse12 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25725 - Critical Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when i... https://www.thehackerwire.com/vulnerability/CVE-2026-25725/ https://t.co/AtFM5um6Nc

    Post summary

    Claude Code's bubblewrap sandboxing flaw in versions before 2.1.2 can expose the .claude/settings.json file, as detailed in the linked vulnerability post.

    71010205
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25725 Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json conf… https://www.cve.org/CVERecord?id=CVE-2026-25725

    Post summary

    The tweet announces CVE‑2026‑25725, noting a sandboxing flaw in Claude Code prior to version 2.1.2, but provides no evidence of exploitation, patching, or a PoC. The information is a straightforward disclosure of a new vulnerability.

    30020191
    56.5K followersView on X
  • 甲斐甲@k_aik_ou
    Disclosure

    📝 新着記事を公開しました settings.local.jsonは守っていたのに、本体は無防備だった 2026年2月、Claude Codeに「sandbox escape via persistent configuration injection in settings.json」という脆弱性(CVE-2026-25725, CVSS 7.7)が報告された^1。サンドボックス内から .claude/settings.js… https://t.co/62uBgPfqGO

    Post summary

    The tweet announces a newly discovered sandbox escape vulnerability in Claude Code (CVE‑2026‑25725) with a CVSS of 7.7, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    10010106
    637 followersView on X
  • Marci Ujlaki@UjlakiMarci
    Disclosure

    hmmmm… NIST assigned max cvss 3.1 score to this vuln, yet GitHub shows 7.7 🟥 CVE-2026-25725, CVSS: 10.0 (#Critical) Claude Code version up to 2.1.1, Anthropic. vulnerability in the bubblewrap sandboxing mechanism malicious code can exploit the absence of the .claude/settings.json file to inject persistent hooks, executing with host privileges upon restart update to version 2.1.2 or later to mitigate this issue https://github.com/anthropics/claude-code/security/advisories/GHSA-ff64-7w26-62rf

    Post summary

    CVE-2026-25725 is a critical privilege‑escalation flaw in Claude Code’s bubblewrap sandbox that exploits a missing settings file; patching to version 2.1.2 or later resolves the issue.

    10010112
    344 followersView on X
  • Prasenjit Sarkar@stretchcloud
    Disclosure

    The attack surface for agentic coding tools just got a proper name: CVE-2026-55607. Claude Code's worktree handling let an attacker name a worktree ".git" and navigate it outside the sandbox context. From there: symlink manipulation plus git fsmonitor execution rewrites ~/.zshenv and you have code execution on the host. Works in read-only permissions mode. Works with the full sandbox on. The entry point is a malicious repo with embedded prompt injection. Clone it, point Claude Code at it, and the rest runs itself. This is the third distinct Claude Code sandbox escape class in 2026. The network allowlist bypass (May 2026) let agents exfiltrate data via protocol manipulation. CVE-2026-25725 used settings.json config injection to persist across sessions. Now the worktree path confusion vector that reaches the host even when you thought the sandbox was airtight. The pattern I keep seeing: the attack surface for coding agents is not the model. It's the filesystem and shell integrations that make agents useful in the first place. Read-only mode, sandboxing, allowlists, none of these form a hard boundary when the tooling around code execution is complex enough. Cursor, Windsurf, Cody, Devin, every tool that wraps an LLM with shell access faces the same structural problem. The boundary between "agent reads files" and "agent runs code" is thinner than any of the sandboxes suggest. The current fix: auto-update. Long-term, the missing piece is deterministic file access auditing at the kernel level, not trust in the agent's own sandbox logic. https://x.com/v_metnew/status/2070369295704482296

    Post summary

    The tweet discloses CVE‑2026‑55607, explaining how worktree handling and symlink manipulation can lead to host code execution, and notes that a fix via auto‑update is recommended.

    00001158
    2.3K followersView on X
  • Ilan Kalendarov@IKalendarov
    Patch

    We found a sandbox escape vulnerability in Claude Code: CVE-2026-25725 What came next was just as revealing. We found the same vulnerability class affecting Gemini CLI and codex cli too. Anthropic engaged, fixed it, and assigned a high-severity CVE.
Google / Gemini CLI had no fix by disclosure.
OpenAI closed it as “informational.” That gap is disappointing, especially when the sandbox is the core trust boundary.

    Post summary

    A CVE‑2026‑25725 sandbox escape was found in Claude Code, Gemini CLI and Codex CLI; Anthropic released a fix, whereas Google and OpenAI either had no fix or treated it as informational.

    10000198
    722 followersView on X
  • CERT Azerbaijan@CERTAzerbaijan
    Disclosure

    “Claude Code” platformasında boşluq (CVE-2026-25725) aşkar olunub. Ətraflı: https://www.instagram.com/p/DUnm1WAivIc/?igsh=MXI3M3J5MnNraHpvYQ== #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/sX6bcnI1LL

    Post summary

    A new vulnerability, CVE-2026-25725, has been identified on the Claude Code platform, with a reference link provided for additional information.

    00010108
    134 followersView on X
  • Decentralizedaz@Decentralizedbz
    General

    @sandworm_cc Very old 2024 bug vs 2026 https://www.cve.org/CVERecord?id=CVE-2026-25725

    Post summary

    The tweet merely references the CVE link with no further context or details.

    1000047
    75 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25725: The Call is Coming from Inside the Sandbox: Escaping Claude Code via Ghost Configs A logic flaw in Anthropic's Claude Code tool allowed sandboxed AI agents to write persistent configuration files to the host system. By exploiting a mis... https://cvereports.com/reports/CVE-2026-25725

    Post summary

    The report announces a logic flaw in Anthropic’s Claude Code that permits sandboxed agents to write persistent config files to the host, but no PoC, exploit, patch, or active exploitation information is provided.

    0001055
    27 followersView on X
  • sipailou@sipailou
    Active Exploitation

    Claude Code 沙箱逃逸漏洞 CVE-2026-25725 拿了 CVSS 10.0(最高危)。攻击者用符号链接绕过工作区沙箱,借 TOCTOU 缺陷写入恶意 hook,下次启动就拿主机完整权限。AI 编程助手从效率工具变成了攻击入口。 #大模型 https://t.co/UQENsl04Sc

    Post summary

    The tweet reports that CVE-2026-25725, a sandbox escape with CVSS 10.0, is being actively exploited via symlink and TOCTOU vulnerabilities, but provides no PoC, exploit code, or patch information.

    0000064
    25 followersView on X
  • Elad Beber@EladBeber
    Disclosure

    We start with a new attack: CBSE (Container-Based Sandbox Escape) Same technique. Multiple vendors: • Anthropic (Claude Code) • Google (Gemini CLI) • OpenAI (Codex CLI) Anthropic acknowledged the severity and assigned CVE-2026-25725 🚨

    Post summary

    The post announces CVE-2026-25725, a container-based sandbox escape affecting Anthropic, Google, and OpenAI, without providing PoC, exploitation evidence, or patch details.

    00000210
    41 followersView on X
  • Marci Ujlaki@UjlakiMarci
    General

    CWE-501: Trust Boundary Violation CWE-668: Exposure of Resource to Wrong Sphere #EUVD: https://euvd.enisa.europa.eu/vulnerability/CVE-2026-25725 #NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-25725

    Post summary

    The post lists CVE-2026-25725 with its CWEs and links to EUVD and NVD but offers no PoC, exploit code, active exploitation, patch, or debunking information.

    0000067
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more