OS Command Injection Vulnerability in Anthropic Claude Code CLI and Agent SDK
CVE-2026-35020
8.6HIGH
What is CVE-2026-35020?
The Anthropic Claude Code CLI and Claude Agent SDK are prone to an OS command injection vulnerability. This occurs through manipulation of the TERMINAL environment variable, enabling local attackers to execute arbitrary commands. By injecting shell metacharacters, malicious users can alter the behavior of the command lookup helper. This vulnerability not only affects normal CLI execution but also the deep-link handler, granting attackers the ability to execute commands with the privileges of the executing user, thereby posing a serious security risk.
Affected Version(s)
Claude Agent SDK for Python 0 <= 0.1.55
Claude Code 0 <= 2.1.91
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Francesco Cipollone
