DFIR Lab[verified]@DFIR_LabPatch
High‑severity OS command injection vulnerability in Anthropic Claude CLI and Agent SDK that can be mitigated by validating the TERMINAL environment variable.
SecureChap[verified]@SecureChapDisclosure
The text discloses three shell injection vulnerabilities in Claude Code 2.1.x that can lead to credential exfiltration, along with technical details, mitigation guidance, and a brief patch strategy.
CVEFind.com@CveFindComDisclosure
A high‑severity OS command injection flaw (CVE‑2026‑35020) in Anthropic Claude CLI and Agent SDKs has been disclosed, allowing local attackers to execute arbitrary commands via a manipulated TERMINAL environment variable.
Infoflowcloud@infoflowcloudDisclosure
The post announces a new OS command injection vulnerability (CVE-2026-35020) affecting Anthropic Claude Code CLI and Claude Agent SDK, detailing the affected components but not providing a PoC or exploit.
CVE@CVEnewDisclosure
The post announces an OS command injection flaw in Anthropic Claude Code CLI and Claude Agent SDK, detailing the vulnerable components but providing no exploit code, active exploitation evidence, or mitigation steps.