Threat Intel

v0.1

← CVEs

CVE-2026-21852

HIGH 7.5
Published
2026-01-21
Last Modified
2026-02-02
Affected Apps
44
Affected Devices
66
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANTHROPIC_BASE_URL to an attacker-controlled endpoint and when the repository was opened, Claude Code would read the configuration and immediately issue API requests before showing the trust prompt, potentially leaking the user's API keys. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.0.65, which contains a patch, or to the latest version.
Affected Devices 66
BRICH7 Windows CONNER5540 Windows DESKTOP-BEVD86P Windows DESKTOP-K6KKAQ1 Windows DESKTOP-OMEN Windows DESKTOP-QDORNBR Windows DPACCT-PF61HQPJ Windows DPAGEC-425083MR Windows DPAGEC-49PL3Q3 Windows DPAGEC-7WBGK74 Windows DPAGEC-BWKPMD4 Windows DPAGEC-BZZHGH4 Windows DPCPD-32SBBY3 Windows DPCUBC-8G7D3H4 Windows DPDISR-FZ5XKH2 Windows DPEMAE-L0243WQL Windows DPHSNG-449500CE Windows DPHSNG-LTSTRING Windows DPHSNG-T800122X Windows DPHSOB-1T48Q54 Windows DPHSOB-61CG0R3 Windows DPHSOB-6KZQN13 Windows DPHSOB-P25253Q6 Windows DPINFT-02609239 Windows DPINFT-1904989 Windows DPINFT-6P663188 Windows DPINFT-8JMDH24 Windows DPINFT-C90GVF4 Windows DPINFT-L2273Y5C Windows DPINFT-PF4T19CJ Windows DPMATH-PW06A9JW Windows DPRCMP-DB57Z64 Windows DPSTUD-V25173P7 Windows DPUWRL-PF5C7SY3 Windows DPVPRS-JBD7LY3 Windows EBB118-22 Windows EBB118-27 Windows EDL-36 Windows F-16 Mac FTB-DL7350-03 Windows FTB-DL7350-08 Windows HTTS171501 Windows LAPTOP-6UP13PGQ Windows LAPTOP-D30CGMB7 Windows LGN-HH-160 Windows LGN-HH-322 Windows STUBER-G0DGQ54 Windows UB-B221T Windows UB-V-218HPLC Windows USULOAN257 Windows YNG-LAB-TPADX1 Windows YOUNG-THINKPAD- Windows a00015523-HL9P9L0MC7 Mac a00344643-K6TXHM3XXM Mac a00367884-D6Q7MJ9CQC Mac a00674610-K174279JG4 Mac a01760171-K4L0J4RM9V Mac a02041378-C4WTVQR03F Mac a02200950-LFJ7WX26VF Mac a02287748-HQHVV125JY Mac a02291312-J4DJC30Y9P Mac a02388352-LQ22WMQLKF Mac a02481579-HFY3Y7Q445 Mac a02483892-GPWGWRXQVC Mac murftastic.local Mac ryan-MacBook-Pro-2023 Mac
References 1