CVE-2026-35022

CRITICAL

Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper

Title source: cna
STIX 2.1

Description

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. Attackers who can influence authentication settings can inject shell metacharacters through parameters like apiKeyHelper, awsAuthRefresh, awsCredentialExport, and gcpAuthRefresh to execute arbitrary commands with the privileges of the user or automation environment, enabling credential theft and environment variable exfiltration.

Exploits (1)

nomisec STUB
by pjordann · poc
https://github.com/pjordann/malicious_test

Scores

CVSS v3 9.8
EPSS 0.0054
EPSS Percentile 67.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (4)
Anthropic/Claude Agent SDK for Python < 0.1.55
Anthropic/Claude Code < 2.1.91
anthropic/claude_agent_sdk < 0.1.55
anthropic/claude_code < 2.1.91
Published Apr 06, 2026
Tracked Since Apr 07, 2026