Flaws in Claude Code Put Developers' Machines at Risk
ID: 025cf55e-cd77-5a06-93b5-0de412d1a419
STIX ID: report--025cf55e-cd77-5a06-93b5-0de412d1a419
Feed Name: Dark Reading
Threat Score
Three critical vulnerabilities in Anthropic's Claude Code allowed repository-controlled configuration files (Hooks and the Model Context Protocol) to run arbitrary commands and exfiltrate API keys, enabling full machine takeover and credential theft; Check Point Research reported the flaws (tracked as CVE-2025-59536 and CVE-2026-21852), and Anthropic released fixes and urged developers to update to the latest version.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
