SSH Remote Development Vulnerability in Claude Desktop from Anthropic
CVE-2026-44467

7.4HIGH

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
13 May 2026

What is CVE-2026-44467?

The Claude Desktop application, designed for SSH remote development, contains a vulnerability that permits an attacker to exploit the SSH connection by failing to validate a server's host key adequately. Versions prior to 1.4304.0 only check for the existence of hostnames in the known_hosts file, without validating the actual server's presented key. This oversight can allow a network adversary to masquerade as a legitimate host and intercept SSH traffic, making connections vulnerable to man-in-the-middle attacks. To mitigate this risk, users are encouraged to update to version 1.4304.0 or later.

Affected Version(s)

claude-code >= 1.2581.0, < 1.4304.0

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.