Known Vulnerabilities for Claude Code by Anthropic
Listed below are 3 of the newest known vulnerabilities associated with "Claude Code" by "Anthropic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-47092 json | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers ... | Not Provided | 2026-05-18 | 2026-05-19 |
| CVE-2026-45136 json | claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (i... | Not Provided | 2026-05-27 | 2026-06-02 |
| CVE-2026-44470 json | The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Pri... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-44467 json | The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Fro... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-44246 json | nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-40068 json | In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file w... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-39861 json | Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes fro... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-35603 json | Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default con... | Not Provided | 2026-04-17 | 2026-04-20 |
| CVE-2026-35021 json | Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code... | Not Provided | 2026-04-06 | 2026-05-29 |
| CVE-2026-31504 json | In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP ra... | Not Provided | 2026-04-22 | 2026-04-27 |