Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharacters into the TERMINAL variable which are interpreted by /bin/sh when the command lookup helper constructs and executes shell commands with shell=true. The vulnerability can be triggered during normal CLI execution as well as via the deep-link handler path, resulting in arbitrary command execution with the privileges of the user running the CLI.
References
| Link | Resource |
|---|---|
| https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/ | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-terminal-environment-variable | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Apr 2026, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:* |
|
| References | () https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/ - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-terminal-environment-variable - Third Party Advisory | |
| First Time |
Anthropic
Anthropic claude Agent Sdk Anthropic claude Code |
06 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 20:16
Updated : 2026-04-29 19:05
NVD link : CVE-2026-35020
Mitre link : CVE-2026-35020
CVE.ORG link : CVE-2026-35020
JSON object : View
Products Affected
anthropic
- claude_code
- claude_agent_sdk
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
