Known Vulnerabilities for Claude Code by Anthropic
Listed below are 6 of the newest known vulnerabilities associated with "Claude Code" by "Anthropic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100585 json | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code p... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-84810 json | claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while i... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82439 json | Description The DRPC server kept a map from function name to request queue and created an entry the first time a function na... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82429 json | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82428 json | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Ma... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82427 json | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor l... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-81836 json | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/int... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-73614 json | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73222 json | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio serve... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-68456 json | In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: wait for pre-firmware load in .dis... | Not Provided | 2026-08-15 | 2026-08-17 |