OS Command Injection Vulnerability in Anthropic Claude Code CLI and Agent SDK
CVE-2026-35020

8.6HIGH

Key Information:

Vendor

Anthropic

Vendor
CVE Published:
6 April 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-35020?

The Anthropic Claude Code CLI and Claude Agent SDK are prone to an OS command injection vulnerability. This occurs through manipulation of the TERMINAL environment variable, enabling local attackers to execute arbitrary commands. By injecting shell metacharacters, malicious users can alter the behavior of the command lookup helper. This vulnerability not only affects normal CLI execution but also the deep-link handler, granting attackers the ability to execute commands with the privileges of the executing user, thereby posing a serious security risk.

Affected Version(s)

Claude Agent SDK for Python 0 <= 0.1.55

Claude Code 0 <= 2.1.91

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Cipollone
.