Anthropics Product Security Update Advisory (CVE-2026-21852)

Anthropics Product Security Update Advisory (CVE-2026-21852)

Overview

 

Anthropics has released a security update that fixes vulnerabilities in its products. Users of affected products are advised to update to the latest version.

 

 

Affected Products

 

CVE-2026-21852

 

Claude Code versions: less than 2.0.65

 

 

Resolved Vulnerabilities

 

API key leakage vulnerability in the Claude Code project loading process (CVE-2026-21852)

 

 

Vulnerability Patches

 

Vulnerability Patches have been made available with the latest update. Please follow the instructions on the Referenced Sites to update to the latest version of Vulnerability Patches.

 

CVE-2026-21852

 

Claude Code Version: 2.0.65

 

 

References

 

[1] Malicious repo configuration can trigger data leakage via environment configuration used before trust confirmation
https://github.com/anthropics/claude-code/security/advisories/GHSA-jh7p-qr78-84p7