CVE-2026-35020

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharacters into the TERMINAL variable which are interpreted by /bin/sh when the command lookup helper constructs and executes shell commands with shell=true. The vulnerability can be triggered during normal CLI execution as well as via the deep-link handler path, resulting in arbitrary command execution with the privileges of the user running the CLI.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:*
cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

History

29 Apr 2026, 19:05

Type Values Removed Values Added
CPE cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*
cpe:2.3:a:anthropic:claude_agent_sdk:*:*:*:*:*:python:*:*
References () https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/ - () https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/ - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-terminal-environment-variable - () https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-terminal-environment-variable - Third Party Advisory
First Time Anthropic
Anthropic claude Agent Sdk
Anthropic claude Code

06 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 20:16

Updated : 2026-04-29 19:05


NVD link : CVE-2026-35020

Mitre link : CVE-2026-35020

CVE.ORG link : CVE-2026-35020


JSON object : View

Products Affected

anthropic

  • claude_code
  • claude_agent_sdk
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')