logo

Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration

ID: 762b46f1-62c8-5bff-9393-8535c725f2ef

STIX ID: report--762b46f1-62c8-5bff-9393-8535c725f2ef

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Check Point researchers disclosed multiple critical vulnerabilities in Anthropic's Claude Code that can execute arbitrary shell commands and exfiltrate Anthropic API keys by opening attacker-controlled repositories that include malicious configuration files (hooks, .mcp.json, claude/settings.json and environment variables). The report cites an unnumbered consent-bypass issue and two tracked CVEs (CVE-2025-59536 — RCE; CVE-2026-21852 — info disclosure), explains how exploitation can occur before trust prompts are shown, and notes fixes shipped in subsequent Claude Code releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.