LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35022

CVE-2026-35022 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 6, 2026

Anthropic Claude Code CLI & Claude Agent SDK - Command Injection

Published: April 6, 2026Updated: April 6, 2026Remote Exploitable

Overview

Anthropic Claude Code CLI and Claude Agent SDK contain a command injection caused by execution of authentication helper configuration values with shell=true without input validation, letting attackers who influence authentication settings execute arbitrary OS commands, exploit requires attacker control over authentication parameters.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Attackers can execute arbitrary OS commands with user or automation environment privileges, leading to credential theft and environment variable exfiltration.

Mitigation

Update to the latest version with input validation for authentication helper execution.

Details

CVE ID
CVE-2026-35022
Severity
Critical
CVSS Score
9.8
Type
command_injection
Status
new

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H