anthropic has 4 CVEs on record. The median CVSS is 5.4 (medium). Most affected products: anthropic (2), claude (1), claude_sdk_for_typescript (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
Worst active — by depth score
CVE-2026-22561High· 7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking43CVE-2026-34451Medium· 5.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications30CVE-2026-34452Medium· 5.3Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape29CVE-2026-34450MediumClaude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool28
anthropic vulnerabilities
CVEs affecting anthropic, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-34452Medium· 5.3Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape
Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape
CVE-2026-34450MediumClaude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
CVE-2026-34451Medium· 5.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated …
CVE-2026-22561High· 7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from …