Skip to content
AnthropicGHSA-h4mw-j7qp-8mwm

Argument Injection via resume Option Allows Arbitrary Command Execution

Critical9.2CVE-2026-96620 · Published Sep 12, 2026 · updated Sep 23, 2026

The Claude Agent SDK for Python passed the `resume` option to the Claude CLI without validation, allowing a value beginning with `-` to be interpreted as a separate CLI flag. An attacker who controlled the `resume` value could inject an `--mcp-config` flag defining a stdio MCP server, resulting in arbitrary command execution at CLI startup that bypassed the SDK's permission controls. Exploitation required an application to pass untrusted input as the session ID to resume. Users are advised to update to the latest version of the claude-agent-sdk package. Thank you to hackerone.com/moamenmahmood for reporting this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
claude-agent-sdk
PyPI
< 0.2.1210.2.121
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-78, CWE-88

More Anthropic advisories

All Anthropic

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.