VulnerabilitiesCritical

Critical OS Command Injection CVE-2026-35022 Found in Anthropic Claude Code CLI

Tuesday, April 7, 2026
Global
NVD

Summary

A critical OS command injection vulnerability (CVSS 9.8) has been discovered in Anthropic Claude Code CLI and Claude Agent SDK, enabling attackers to execute arbitrary system commands. The flaw affects AI development tools widely used by developers integrating Claude AI capabilities.

Threat Analysis

CVE-2026-35022 is a critical OS command injection vulnerability (CVSS 9.8) affecting Anthropic Claude Code CLI and Claude Agent SDK. The vulnerability allows attackers to inject and execute arbitrary operating system commands through the affected tools, potentially leading to full system compromise. Given the widespread adoption of Claude AI tools in software development workflows, this vulnerability poses significant risk to developer environments, CI/CD pipelines, and production systems where these tools are deployed. The flaw was published in the NVD on April 6-7, 2026. This vulnerability is particularly concerning in the context of AI-assisted development environments where these tools often have elevated privileges and access to sensitive credentials and source code. Recommended mitigations: Apply available patches from Anthropic immediately, restrict Claude Code CLI usage to isolated environments, audit CI/CD pipelines for Claude tool integrations, implement least-privilege principles for AI development tools, and monitor for anomalous command execution.

Last updated: Apr 7, 2026, 08:18 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM