Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and outside the threat model of CLI tools.
CVSS
No CVSS.
References
No reference.
Configurations
No configuration.
History
29 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
| CWE | ||
| CPE | cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:* |
|
| Summary | (en) Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and outside the threat model of CLI tools. |
29 Apr 2026, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:* |
|
| References | () https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/ - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-terminal-environment-variable - Third Party Advisory | |
| First Time |
Anthropic
Anthropic claude Agent Sdk Anthropic claude Code |
06 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 20:16
Updated : 2026-05-29 18:16
NVD link : CVE-2026-35020
Mitre link : CVE-2026-35020
CVE.ORG link : CVE-2026-35020
JSON object : View
Products Affected
No product.
CWE
No CWE.
