Vulnerabilidades en anthropics
36 resultadosAnálisis Vexday
A Anthropic apresenta 36 vulnerabilidades conhecidas na base do Vexday, com 10 publicadas nos últimos 90 dias, indicando descobertas recentes contínuas. Nenhuma vulnerabilidade está sob ataque ativo (KEV) nem foi classificada como crítica, reduzindo o risco imediato de exploração em larga escala. A fraqueza dominante é CWE-78 (injeção de comandos do sistema operacional), exigindo atenção na validação de entrada em processamento de dados.
CVE-2026-24053HIGHCluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File WritesEPSS 0.5%CVE-2026-25723HIGHClaude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write RestrictionsEPSS 0.5%CVE-2025-55284HIGHClaude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude CodeEPSS 0.5%CVE-2025-59829LOWClaude Code: Permission deny bypass is possible through symlinkEPSS 0.4%CVE-2026-24052HIGHClaude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled DomainsEPSS 0.4%CVE-2026-34451MEDIUMClaude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling DirectoriesEPSS 0.4%CVE-2025-59828HIGHClaude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn VersionsEPSS 0.4%CVE-2025-52882HIGHClaude Code IDE extensions allow websocket connections from arbitrary originsEPSS 0.3%CVE-2026-44467HIGHClaude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote SessionsEPSS 0.2%CVE-2026-55406MEDIUMBuffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefEPSS 0.2%CVE-2026-34450MEDIUMClaude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory ToolEPSS 0.2%CVE-2026-44470HIGHClaude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMServiceEPSS 0.2%CVE-2026-46406MEDIUMClaude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File WriteEPSS 0.2%CVE-2026-35603MEDIUMClaude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsEPSS 0.2%CVE-2026-34452MEDIUMClaude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox EscapeEPSS 0.1%CVE-2026-41686MEDIUMClaude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory ToolEPSS 0.1%