🇬🇧The Register - AI/ML•較早收集於 28m
Claude Code 漏洞導致遠端程式碼執行

💡Claude Code RCE vuln via tainted repos stole API keys—patched, but AI dev tools risky.
⚡ 30-Second TL;DR
有什麼變化
Claude Code 漏洞允許遠端程式碼執行
為什麼重要
暴露 AI 編碼協作工具風險,可能危害開發環境及敏感金鑰。使用者須嚴格審查儲存庫。突顯 AI 輔助開發的安全挑戰。
下一步行動
Audit repositories for malicious configs before cloning into Claude Code.
誰應關注:Developers & AI Engineers
關鍵要點
- •Claude Code 漏洞允許遠端程式碼執行
- •注入儲存庫惡意設定進行攻擊
- •開發者克隆開啟專案時竊取 API 金鑰
- •Anthropic 已修補特定漏洞
- •AI 協作工具仍有更廣攻擊面
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 7 個來源。
🔑 增強重點摘要
- •Vulnerabilities specifically exploited Hooks in .claude/settings.json, Model Context Protocol (MCP) servers, and environment variables to execute shell commands[1][3].
- •Check Point Research disclosed the issues and collaborated with Anthropic for remediation, with patches applied before public publication[1].
- •Anthropic implemented an enhanced warning dialog for untrusted configurations and plans additional granular risk controls[1].
- •Attackers could leverage stolen API keys for billing fraud or accessing Workspaces to manipulate shared projects and data[1][3].
🛠️ 技術深入
- •CVE-2025-59536 and CVE-2026-21852: No user consent bypass via untrusted .claude/settings.json hooks enabling arbitrary code execution (fixed in v1.0.87, Sep 2025; CVSS 8.7)[1][3].
- •CVE-2026-21852: Info disclosure in project-load flow by setting ANTHROPIC_BASE_URL to attacker endpoint, leaking API keys pre-trust prompt (fixed in v2.0.65, Jan 2026; CVSS 5.3)[3].
- •CVE-2026-25722: Path traversal via cd commands bypassing write protections in .claude directory for file tampering (affected <v2.0.57; published 2026-02-06)[2].
🔮 前景展望AI analysis grounded in cited sources
AI coding tools will require mandatory trust prompts for all project configs
Anthropic's enhanced warning dialog and planned granular controls set a precedent to mitigate untrusted repo risks before execution[1].
Stolen AI API keys enable Workspace access for deeper infrastructure compromise
⏳ 時間線
2025-09
No CVE hook vulnerability fixed in Claude Code v1.0.87
2026-01
CVE-2026-21852 API key exfiltration fixed in v2.0.65
2026-02-06
CVE-2026-25722 path traversal published to NVD
2026-02-09
CVE-2026-25722 last updated in NVD
2026-02
Check Point discloses RCE flaws (CVE-2025-59536, CVE-2026-21852); Anthropic patches
2026-02-05
Claude Opus 4.6 research reveals 500+ zero-days; Claude Code Security preview launched
📎 來源 (7)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- research.checkpoint.com — Rce and API Token Exfiltration Through Claude Code Project Files Cve 2025 59536
- sentinelone.com — Cve 2026 25722
- thehackernews.com — Claude Code Flaws Allow Remote Code
- futurumgroup.com — Claude Found 500 Zero Days Who Patches Them Before Attackers Arrive
- snyk.io — Claude Code Remediation Loop Evolution
- Anthropic — Claude Code Security
- Anthropic — Claude Opus 4 6 Risk Report
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: The Register - AI/ML ↗
每週 AI 簡報
每週一封,可隨時退訂。