SSH Remote Development Vulnerability in Claude Desktop from Anthropic
CVE-2026-44467
7.4HIGH
What is CVE-2026-44467?
The Claude Desktop application, designed for SSH remote development, contains a vulnerability that permits an attacker to exploit the SSH connection by failing to validate a server's host key adequately. Versions prior to 1.4304.0 only check for the existence of hostnames in the known_hosts file, without validating the actual server's presented key. This oversight can allow a network adversary to masquerade as a legitimate host and intercept SSH traffic, making connections vulnerable to man-in-the-middle attacks. To mitigate this risk, users are encouraged to update to version 1.4304.0 or later.
Affected Version(s)
claude-code >= 1.2581.0, < 1.4304.0
