Patched Claude Code Flaws Allowed API Key Theft and Code Execution Before Trust Prompt
Two security vulnerabilities, CVE-2026-21852 and CVE-2025-59536, were discovered in Anthropic's Claude Code CLI tool affecting versions prior to 2.0.65. The flaws stemmed from an order-of-operations defect in which the CLI merged project-level configuration files before presenting users with a trust confirmation prompt. This pre-trust execution window allowed a malicious repository to silently redirect API requests to an attacker-controlled server, exposing the developer's Anthropic API key in plaintext. Beyond credential theft, the same window enabled attackers to embed malicious lifecycle hooks in repository config files, triggering arbitrary code execution on the developer's machine at session start. The vulnerabilities were addressed in version 2.0.65, which enforces directory trust evaluation before any project-level configuration is loaded or executed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in