anthropic-ai has 3 CVEs on record. 2 were published in the last 90 days.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution41CVE-2026-54316MediumClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch40CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write28
anthropic-ai vulnerabilities
CVEs affecting anthropic-ai, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.55%via GHSA
CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
▾ Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.52%via GHSA