CVE-2026-21852
Claude Code vulnerability analysis and mitigation

Overview

CVE-2026-21852 is a credential exfiltration vulnerability in Anthropic's Claude Code agentic coding tool, classified as "Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation." Prior to version 2.0.65, Claude Code's project-load flow would read repository configuration files and issue API requests — including transmitting the user's Anthropic API keys — before displaying the trust confirmation prompt to the user. The vulnerability affects all versions of the @anthropic-ai/claude-code npm package below 2.0.65. It was published on January 20, 2026, and received a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Anthropic Advisory).

Technical details

The root cause is classified as CWE-522 (Insufficiently Protected Credentials) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Claude Code's project-load flow failed to enforce a trust boundary before processing repository-supplied configuration: when a user opened a directory in Claude Code, the tool would read any present settings file and apply environment variables — including ANTHROPIC_BASE_URL — prior to presenting the trust prompt. An attacker who controls a repository can place a settings file that redirects ANTHROPIC_BASE_URL to an attacker-controlled server; Claude Code then issues API requests (carrying the user's API key in the Authorization header) to that server before the user has any opportunity to review or reject the repository. This is a time-of-check/time-of-use (TOCTOU) design flaw in the trust model, requiring only that the victim open the malicious repository with Claude Code (Github Advisory, Anthropic Advisory).

Impact

Successful exploitation results in the silent exfiltration of the victim's Anthropic API key to an attacker-controlled server, with no visible indication to the user. With a stolen API key, an attacker can make unauthorized API calls billed to the victim's account, access any data or capabilities the key permits, and potentially pivot to other systems or services if the same credentials are reused. The attack requires minimal user interaction — simply opening a malicious repository in Claude Code is sufficient to trigger the leak — making it particularly dangerous in developer workflows involving third-party or open-source repositories (Github Advisory, Check Point Research).

Exploitability

Multiple public proof-of-concept exploits are available on GitHub, including repositories at https://github.com/atiilla/CVE-2026-21852-PoC and https://github.com/snoopysecurity/CVE-2026-21852-PoC, added as early as March 2, 2026 (Feedly). The vulnerability is also indexed on Sploitus. As of the advisory, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.033–0.041%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Nessus detection plugin 305985 is available for scanning (Tenable).

Exploitation steps

  1. Create a malicious repository: The attacker creates or compromises a code repository and adds a Claude Code settings file (e.g., .claude/settings.json or equivalent project-level configuration) that sets ANTHROPIC_BASE_URL to an attacker-controlled HTTPS endpoint (e.g., https://attacker.example.com/api).
  2. Set up a credential-harvesting server: The attacker configures a server at the specified URL to log all incoming HTTP requests, particularly the Authorization header, which will contain the victim's Anthropic API key in Bearer token format.
  3. Distribute the malicious repository: The attacker publishes the repository publicly (e.g., on GitHub), shares it via social engineering, or submits it as a pull request or dependency to a project the target developer uses.
  4. Victim opens the repository: The target developer clones or navigates to the repository directory and runs claude (Claude Code). Claude Code reads the repository's settings file and applies the ANTHROPIC_BASE_URL override before displaying the trust prompt.
  5. API key exfiltration: Claude Code issues an API request to the attacker-controlled endpoint, transmitting the victim's Anthropic API key in the request headers — before the user sees or can respond to any trust confirmation dialog.
  6. Credential abuse: The attacker harvests the API key from server logs and uses it to make unauthorized API calls, access model outputs, or incur charges on the victim's account (Github Advisory, Check Point Research).

Indicators of compromise

  • Network: Outbound HTTPS requests from the developer's workstation to unexpected or unknown domains immediately upon opening a repository with Claude Code; API requests to non-Anthropic endpoints (i.e., not api.anthropic.com) carrying Authorization: Bearer sk-ant-... headers.
  • File System: Presence of a .claude/settings.json or equivalent Claude Code project settings file in a repository containing an ANTHROPIC_BASE_URL key pointing to an external or unfamiliar domain.
  • Logs: Claude Code application logs showing API requests issued before the trust prompt was displayed or confirmed; network proxy logs capturing requests to non-standard Anthropic API endpoints.
  • API Usage: Unexpected or unauthorized API usage appearing in the Anthropic console/billing dashboard, particularly from IP addresses not associated with the user's normal activity (Github Advisory).

Mitigation and workarounds

Anthropic has released a patch in Claude Code version 2.0.65, which ensures that repository configuration files are not processed and API requests are not issued until after the user confirms trust for the repository. Users on standard Claude Code auto-update have already received this fix automatically. Users performing manual updates should upgrade to version 2.0.65 or later immediately via their preferred installation method (curl installer, Homebrew, WinGet, or npm). As an interim workaround, users should avoid opening repositories from untrusted or unknown sources in Claude Code, and should inspect any .claude/settings.json or equivalent configuration files for unexpected ANTHROPIC_BASE_URL entries before running Claude Code. Any API keys potentially exposed should be rotated immediately via the Anthropic console (Github Advisory, Anthropic Advisory).

Community reactions

Check Point Research published a detailed technical write-up covering CVE-2026-21852 alongside a related RCE vulnerability (CVE-2025-59536), describing how malicious repository files could turn Claude Code into an attack vector for API key theft and remote code execution (Check Point Research). The disclosure received broad coverage from outlets including The Hacker News, The Register, Security Affairs, BankInfoSecurity, and IT Pro, with community discussion active on Reddit's r/blueteamsec, r/Anthropic, and r/CVEWatch. Security researchers on Mastodon and Bluesky highlighted the vulnerability as a cautionary example of trust-model failures in AI coding agents. The vulnerability was featured in F5 Labs' weekly threat bulletin and Check Point's AI threat landscape digest for March–April 2026, reflecting sustained industry attention to AI tool supply chain risks (The Hacker News, Check Point Research).

Additional resources


SourceThis report was generated using AI

Related Claude Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55607HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026
CVE-2026-40068HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesMay 05, 2026
CVE-2026-39861HIGH7.7
  • Claude Code logoClaude Code
  • @anthropic-ai/claude-code
NoYesApr 21, 2026
CVE-2026-54316MEDIUM6
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 23, 2026
CVE-2026-46406MEDIUM4.4
  • MinimOS logoMinimOS
  • claude-cli
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management