DFIR Lab[verified]@DFIR_LabPatch
Anthropic’s Claude Code CLI & Agent SDK are vulnerable to CVE‑2026‑35022, an OS command injection flaw; patches are available and essential to prevent attackers from executing arbitrary commands.
SecureChap[verified]@SecureChapDisclosures
The post discloses multiple shell‑injection vulnerabilities in Claude Code 2.1.x, provides technical details and CVSS scores, and suggests remediation steps, but does not present a PoC, active exploitation evidence, or a false‑positive claim.
CrustyTL;DR@CrustyTLDRDisclosure
A code leak has exposed a critical command‑injection vulnerability (CVE‑2026‑35022) in Anthropic's Claude AI, but no proof of exploitation, patches, or PoC details are provided.
CVEFind.com@CveFindComDisclosure
This post announces a critical OS command injection vulnerability (CVE-2026-35022) in Anthropic Claude Code CLI/Agent SDK that allows arbitrary command execution and credential theft.
CVE@CVEnewDisclosure
The post announces CVE-2026-35022, identifying an OS command injection flaw in Anthropic’s Claude Code CLI and Agent SDK, with no evidence of exploitation or remediation discussed.
CCB Alert@CCBalertDisclosure
A warning that CVE-2026-35022, a high‑severity OS command injection flaw in Anthropic Claude Code CLI & Agent SDK, can allow arbitrary command execution and data theft. No PoC, exploit code, or patch details are provided.
Infoflowcloud@infoflowcloudDisclosure
A new OS command injection vulnerability (CVE‑2026‑35022) affecting Anthropic Claude CLI and SDK has been disclosed with a link to the official CVE record.
0day Signal@0dayPublishingDisclosure
The tweet announces a new CVE-2026-35022 affecting Anthropic Claude’s auth helpers, where user input is executed directly, potentially compromising CI/CD pipelines. No PoC, patch, or exploitation evidence is provided.