CVE-2026-25725

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was mounted as writable and .claude/settings.local.json was explicitly protected with read-only constraints, settings.json was not protected if it was missing. This allowed malicious code running inside the sandbox to create this file and inject persistent hooks (such as SessionStart commands) that would execute with host privileges when Claude Code was restarted. This issue has been patched in version 2.1.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Claude Code es una herramienta de codificación agéntica. Antes de la versión 2.1.2, el mecanismo de sandboxing bubblewrap de Claude Code no protegió adecuadamente el archivo de configuración .claude/settings.json cuando no existía al inicio. Si bien el directorio padre estaba montado como escribible y .claude/settings.local.json estaba explícitamente protegido con restricciones de solo lectura, settings.json no estaba protegido si faltaba. Esto permitía que código malicioso ejecutándose dentro del sandbox creara este archivo e inyectara hooks persistentes (como comandos SessionStart) que se ejecutarían con privilegios de host cuando se reiniciara Claude Code. Este problema ha sido parcheado en la versión 2.1.2.

09 Feb 2026, 14:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0
First Time Anthropic
Anthropic claude Code
References () https://github.com/anthropics/claude-code/security/advisories/GHSA-ff64-7w26-62rf - () https://github.com/anthropics/claude-code/security/advisories/GHSA-ff64-7w26-62rf - Third Party Advisory
CPE cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

06 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 18:16

Updated : 2026-06-17 10:25


NVD link : CVE-2026-25725

Mitre link : CVE-2026-25725

CVE.ORG link : CVE-2026-25725


JSON object : View

Products Affected

anthropic

  • claude_code
CWE
CWE-501

Trust Boundary Violation

CWE-668

Exposure of Resource to Wrong Sphere