Critical vulnerabilities in Anthropic's Claude Code

Check Point Research ( CPR ) has discovered critical security vulnerabilities in Claude Code , Anthropic ’s software development tool used by tens of millions of users monthly. The vulnerabilities could allow malicious actors to remotely execute code and obtain API keys – simply by forcing a developer to open a compromised code repository.

All findings were responsibly reported in anthropic and they have already been corrected.

See more articles from iGuRu.gr when you search for news on Google.

The Main Findings

  • Execute commands without notification (CVE-2025-59536): Automation mechanisms Claude Code could be activated silently during the startup of a TECHNOLOGY, executing hidden commands shell without any visible notification to the developer.
  • Bypassing user consent: Repository settings could bypass built-in approval checks MCP (Model Context Protocol), allowing external services to run before the user gives permission.
  • Theft of keys API (CVE-2026-21852): The traffic API – including full headers authentication – could be redirected to server under the attacker's control, before the user even confirms that they trust the TECHNOLOGY.
  • Broader impact in corporate environments: A single stolen key API in corporate work space anthropic could allow access, modification, or deletion of shared files, as well as the creation of unauthorized charges.

What does she say? Check Point

“This research highlights a fundamental shift in how we approach risk in the age of artificial intelligence. AI- powered software development tools are no longer peripherals they are becoming core infrastructure. Organizations that are rapidly adopting AI must ensure that their security model evolves at the same pace.” – Oded Vanunu , Head of Product Vulnerability Research , Check Point

What Was Fixed?

In collaboration with Anthropic , Check Point Research immediately notified the company of the findings. Anthropic implemented fixes that:

  • Strengthened user trust approval processes
  • They prohibited the execution of external tools before explicit approval
  • They blocked communications API until the user's consent is confirmed in TECHNOLOGY

The Bigger Picture: New Risks in the Supply Chain AI

The findings reflect a broader shift in how software supply chains operate. Repository configuration files, traditionally treated as inert metadata, now have the potential to influence execution, networking, and access permissions. In the age of AI , security is not just about preventing malicious code—it’s about understanding how the very levels of automation are changing the rules.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).