Anthropic has 5 CVEs on record. 1 was published in the last 90 days. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. Most affected products: anthropic (2), @anthropic-ai/claude-code (1), claude (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Products
- anthropic 2
- @anthropic-ai/claude-code 1
- claude 1
- claude_sdk_for_typescript 1
Worst active — by depth score
CVE-2026-22561High· 7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking43CVE-2026-34451Medium· 5.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications30CVE-2026-34452Medium· 5.3Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape29CVE-2026-34450MediumClaude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool28CVE-2026-103012Low· 2.0Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-man…11
Anthropic vulnerabilities
CVEs affecting Anthropic, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-103012Low· 2.0Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-man…
Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-man…
CVE-2026-34452Medium· 5.3Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape
Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape
CVE-2026-34450MediumClaude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
CVE-2026-34451Medium· 5.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated …
CVE-2026-22561High· 7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from …