This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade Anthropic Claude Agent SDK for Python to the latest released version that contains the vendor fix.
- Upgrade the Anthropic Claude Code CLI to the patched release as soon as possible.
- If an immediate upgrade is not feasible, limit execution of the CLI to trusted users and audit any file path inputs for suspicious characters.
- Monitor vendor advisories and security channels for additional guidance or temporary workarounds.
Generated by OpenCVE AI on April 7, 2026 at 01:41 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Fri, 29 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Anthropic claude Agent Sdk
|
|
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts | |
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions into file paths that are interpolated into shell commands executed via execSync. Although the file path is wrapped in double quotes, POSIX shell semantics (POSIX §2.2.3) do not prevent command substitution within double quotes, allowing injected expressions to be evaluated and resulting in arbitrary command execution with the privileges of the user running the CLI. | This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 29 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropic claude Agent Sdk
|
|
| CPEs | cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:* cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Anthropic claude Agent Sdk
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropic
Anthropic claude Agent Sdk For Python Anthropic claude Code |
|
| Vendors & Products |
Anthropic
Anthropic claude Agent Sdk For Python Anthropic claude Code |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions into file paths that are interpolated into shell commands executed via execSync. Although the file path is wrapped in double quotes, POSIX shell semantics (POSIX §2.2.3) do not prevent command substitution within double quotes, allowing injected expressions to be evaluated and resulting in arbitrary command execution with the privileges of the user running the CLI. | |
| Title | Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T16:26:11.666Z
Reserved: 2026-03-31T20:40:15.618Z
Link: CVE-2026-35021
Updated:
Status : Rejected
Published: 2026-04-06T20:16:25.067
Modified: 2026-05-29T18:16:44.543
Link: CVE-2026-35021
No data.
OpenCVE Enrichment
Updated: 2026-04-07T09:37:42Z
No weakness.