Martin Musiol[verified]@musiol_martinPatch
CVE-2026-35021 is an OS command injection vulnerability affecting Claude Code CLI and Agent SDK, with patch 2.0.65 available; the issue involves attacker-controlled file paths that trigger shell execution.
DFIR Lab[verified]@DFIR_LabDisclosure
The tweet announces a high‑severity (CVSS 7.8) vulnerability, CVE-2026-35021, in Anthropic Claude Code CLI & Agent SDK that allows OS command injection via malicious file paths; it provides technical details but no exploit, patch, or claim of active exploitation.
SecureChap[verified]@SecureChapDisclosure
The post announces the discovery of four CLI and/editor related shell injection vulnerabilities in Claude Code, details their technical root causes, and provides a mitigation recommendation.
タカミ|製造業の営業企画×広報[verified]@eigyo_koho_mfgDisclosure
The post announces the disclosure of CVE-2026-35021, an OS command injection leading to remote code execution in Claude Code’s CLI, noting a 512,000‑line source leak due to human error but providing no exploit code, active exploitation evidence, or patch details.
CVE@CVEnewDisclosure
The text announces the CVE‑2026‑35021 disclosure, noting an OS command injection flaw in Anthropic Claude tools, but provides no PoC, exploit, or mitigation details.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑35021, describing an OS command injection flaw in Anthropic Claude components, but does not provide any PoC, exploit, patch, or evidence of active exploitation.