‹ Back to Home

Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration — Check Point Research Exposes Critical Vulnerabilities

Check Point Research has discovered critical vulnerabilities in Anthropic's Claude Code: CVE-2025-59536 (Hooks and MCP exploit allowing remote code execution) and CVE-2026-21852 (API key exfiltration via ANTHROPIC_BASE_URL override). A single malicious commit in a repository can compromise any developer who clones and opens it in Claude Code. Hooks execute automatically without consent, MCP servers can bypass safeguards, and API keys are exposed in plaintext.

Keerthika 6 min read 2,758
Follow on Google
Updated 5 months ago
Security Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration — Check Point Research Exposes Critical Vulnerabilities 6 min left Follow on Google
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration — Check Point Research Exposes Critical Vulnerabilities

TamilTech AI summary

Check Point Research disclosed two critical flaws in Anthropic’s Claude Code (CVE-2025-59536 and CVE-2026-21852) that can lead to remote code execution and Anthropic API key theft when a developer simply clones a malicious repo and opens it in the tool. The first issue abuses project Hooks and MCP settings so harmful commands can run and trust prompts can be bypassed; the second lets a project override `ANTHROPIC_BASE_URL` so API traffic—and the key in the auth header—goes to an attacker who can still proxy real responses so nothing looks wrong. That matters because it is a quiet supply-chain hit on the developer’s own machine, source, and credentials, not a far-off server breach. Anthropic has shipped fixes, but only people on the latest Claude Code build are protected, so older installs stay exposed. Update Claude Code right away, inspect `.claude/` and `.mcp.json` before you trust a project, rotate your API key if you opened untrusted repos, prefer system-level keys over project config, and watch your Anthropic usage for odd spikes.

  • What are CVE-2025-59536 and CVE-2026-21852?
  • How can I protect myself from these vulnerabilities?
  • Has Anthropic fixed these vulnerabilities?
  • Are other AI coding tools affected?

AI-assisted summary, checked by the TamilTech editorial team.

Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration — Two Critical CVEs Expose AI Coding Tool's Dark Side

AI coding assistants have become indispensable tools for developers worldwide. But what happens when the tool you trust to write your code becomes the vector through which your entire development environment is compromised? Check Point Research has answered that question with a devastating disclosure: two critical vulnerabilities in Anthropic's Claude Code — CVE-2025-59536 and CVE-2026-21852 — that allow attackers to achieve remote code execution and steal API credentials simply by getting a developer to clone a malicious repository.

This is not a theoretical attack. The vulnerabilities exploit legitimate Claude Code features — Hooks, Model Context Protocol (MCP) servers, and environment variables — turning them into weapons that execute arbitrary shell commands and exfiltrate Anthropic API keys the moment a developer opens an untrusted project.

Premium Content

You've read all your free articles today. Subscribe to continue reading.

You've used 3 of 3 free articles today.

Subscribe Now

Already subscribed? Sign in

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications