Skip to content

Anthropic security advisories

40 advisories · 18 critical or high in 12 months · latest Sep 25

40 advisories

Advisory
Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host
High8.5Sep 25
Argument Injection via resume Option Allows Arbitrary Command Execution
Critical9.2Sep 12
Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Medium6.3Jul 1
Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Medium5.9Jul 1
Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
Medium4.4Jun 25
Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
High7.7Jun 25
Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Medium6.0Jun 13
Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Medium5.3May 20
SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
High7.4May 6
Local Privilege Escalation via Directory Junction in CoworkVMService
High8.5May 6
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
Medium4.8Apr 24
Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
High7.7Apr 24
Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
High7.7Apr 20
Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Medium5.4Apr 17
Memory Tool Path Validation Race Condition Allows Sandbox Escape
Medium5.8Mar 31
Insecure Default File Permissions in Local Filesystem Memory Tool
Medium4.8Mar 31
Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories
Medium6.3Mar 31
Workspace Trust Dialog Bypass via Repo-Controlled Settings File
High7.7Mar 18
Command Injection via Directory Change Bypasses Write Protection
High7.7Feb 6
Command Injection via Piped sed Command Bypasses File Write Restrictions
High7.7Feb 6
Sandbox Escape via Persistent Configuration Injection in settings.json
High7.7Feb 6
Permission Deny Bypass Through Symbolic Links
Low2.3Feb 6
Command Injection in find Command Bypasses User Approval Prompt
High7.7Feb 3
Path Restriction Bypass via ZSH Clobber Allows Arbitrary File Writes
High7.7Feb 3
Domain Validation Bypass Allows Automatic Requests to Attacker-Controlled Domains
High7.1Feb 3
Anthropic: information disclosure
Medium5.3Jan 20
Network Sandboxing Escape
Low1.8Dec 4, 2025
Command Validation Bypass Allows Arbitrary Code Execution
High8.7Dec 3, 2025
Sed Command Validation Bypass Allows Arbitrary File Writes
High8.7Nov 20, 2025
Command execution prior to Claude Code startup trust dialog
High7.7Nov 19, 2025
Command execution prior to Claude Code startup trust dialog
High8.7Oct 3, 2025
Permission deny bypass through symlink
Low2.3Oct 3, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High7.7Sep 24, 2025
Command Injection in Claude Code rg command allowed bypass of user approval prompt for command execution
High8.7Sep 9, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High8.7Sep 9, 2025
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
High8.7Sep 2, 2025
Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
High7.1Aug 15, 2025
Anthropic: path traversal
High7.7Aug 1, 2025
Command Injection in Claude Code echo command allowed bypass of user approval prompt for command execution
High8.7Aug 1, 2025
Claude Code IDE extensions allow websocket connections from arbitrary origins
High8.8Jun 23, 2025
About Anthropic

Security advisories Anthropic publishes for its own products.

Anthropic elsewhere on fru.dev: Acquisitions · Funding · Paydays · Releases · TechConf · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.