Summary
CVE-2026-35021 is a high-severity OS command injection vulnerability affecting Anthropic Claude Code CLI and Claude Agent SDK, caused by improper handling of file paths in the prompt editor invocation process. Attackers can craft file names containing shell metacharacters like $() or backticks, which are still interpreted due to POSIX shell behavior even when enclosed in double quotes, leading to execution of arbitrary commands with the privileges of the user running the CLI.
The issue requires user interaction to trigger and impacts versions up to 2.1.91 (Claude Code CLI) and 0.1.55 (Claude Agent SDK for Python), making updates and proper input validation essential to reduce risk.
Urgent Actions Required
- Update to versions beyond 2.1.91 (CLI) and 0.1.55 (SDK).
- Sanitize all file path inputs.
- Avoid using user input in shell commands.
- Review systems that may have processed untrusted file paths or inputs through the affected components.
- Limit user privileges for accounts running the CLI to reduce potential impact.
Which Systems Are Vulnerable to CVE-2026-35021?
Technical Overview
- Vulnerability Type: OS Command Injection (CWE-78)
-
Affected Software/Versions:
- Claude Code CLI (up to version 2.1.91)
- Claude Agent SDK for Python (up to version 0.1.55)
-
CVSS Vector: v4.0
- Attack Vector (AV): Local
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): Active
- Vulnerable System Confidentiality (VC): High
- Vulnerable System Integrity (VI): High
- Vulnerable System Availability (VA): High
- Subsequent System Confidentiality (SC): None
- Subsequent System Integrity (SI): None
- Subsequent System Availability (SA): None
- Patch Availability: Yes, available
How Does the CVE-2026-35021 Exploit Work?
The attack typically follows these steps:
What Causes CVE-2026-35021?
Vulnerability Root Cause:
This issue arises from improper handling of user-influenced file paths in the prompt editor invocation logic. The application constructs shell commands using these file paths and executes them via functions like execSync without adequately neutralizing special characters. Although the input is enclosed in double quotes, POSIX shell behavior still allows command substitution through patterns such as $() and backticks. As a result, crafted file paths can introduce unintended commands, leading to execution with the same privileges as the user running the CLI.
How Can You Mitigate CVE-2026-35021?
If immediate patching is delayed or not possible:
- Validate and sanitize all file path inputs before they are used by the CLI.
- Avoid constructing shell commands with user-controlled input and use safer execution methods where possible.
- Review any systems that may process untrusted file paths through the prompt editor functionality.
- Restrict the privileges of users running the CLI to limit the impact of potential exploitation.
Which Assets and Systems Are at Risk?
-
Asset Types Affected:
- Developer environments using Claude Code CLI
- Systems utilizing the Claude Agent SDK for Python
- Workflows where file paths are processed through the prompt editor functionality
-
Business-Critical Systems at Risk:
- Developer workstations where the CLI is executed
- Environments handling sensitive data accessible via CLI operations
- CI/CD environments where these tools are used and may process untrusted inputs
-
Exposure Level:
- Local systems where users interact with the CLI and open or process file paths
- Development and CI/CD setups that handle external or untrusted file inputs
How Can You Detect CVE-2026-35021 Exploitation?
Exploitation Signatures:
Look for file paths containing shell expressions like $() or backticks being processed by the CLI.
Indicators of Compromise (IOCs/IOAs):
- Execution of unexpected commands triggered via file path handling
- Unusual behavior when opening or processing files through the CLI
Behavioral Indicators:
- Commands executed during prompt editor invocation
- File path inputs leading to unintended system actions
Alerting Strategy:
- Monitor for abnormal command execution linked to file path processing
- Flag unexpected shell activity under CLI processes
Remediation & Response
-
Remediation Timeline:
- Immediate: Upgrade to versions beyond Claude Code CLI 2.1.91 and Agent SDK 0.1.55.
- Post-update: Review systems that handled untrusted file paths and validate inputs.
-
Incident Response Considerations:
- Review systems where untrusted file paths were processed
- Check for signs of unintended command execution
- Limit user privileges and validate inputs after patching
Keep Exploring
Detailed insights into critical and emerging CVEs
References: