[go: up one dir, main page]

Insufficiently Protected Credentials Affecting @anthropic-ai/claude-code package, versions <2.0.65


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ANTHROPICAICLAUDECODE-15046268
  • published21 Jan 2026
  • disclosed21 Jan 2026
  • creditUnknown

Introduced: 21 Jan 2026

NewCVE-2026-21852  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade @anthropic-ai/claude-code to version 2.0.65 or higher.

Overview

@anthropic-ai/claude-code is an Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the project-load flow. An attacker can obtain sensitive information, such as API keys, by tricking a user into opening a malicious repository containing a settings file that sets the ANTHROPIC_BASE_URL to an attacker-controlled endpoint, causing API requests to be sent before trust is confirmed.

References

CVSS Base Scores

version 4.0
version 3.1