@anthropic-ai/claude-code vulnerabilities
CVEs whose affected-version data names the @anthropic-ai/claude-code package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.55%via GHSA
CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
▾ Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.52%via GHSA