CVE-2026-35022 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 6, 2026
Anthropic Claude Code CLI & Claude Agent SDK - Command Injection
Published: April 6, 2026Updated: April 6, 2026Remote Exploitable
Overview
Anthropic Claude Code CLI and Claude Agent SDK contain a command injection caused by execution of authentication helper configuration values with shell=true without input validation, letting attackers who influence authentication settings execute arbitrary OS commands, exploit requires attacker control over authentication parameters.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute arbitrary OS commands with user or automation environment privileges, leading to credential theft and environment variable exfiltration.
Mitigation
Update to the latest version with input validation for authentication helper execution.
References
Related Resources
Details
- CVE ID
- CVE-2026-35022
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- new
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H