Skip to main content
← Back to sources

Check Point Research: Claude Code CVEs Enable RCE and API Token Exfiltration Through Repository Config Files

Published 2026-02-25Ingested 2026-05-06AI Engineering PracticesHigh

Summary

Check Point Research disclosed two critical vulnerabilities in Anthropic's Claude Code (CVE-2025-59536 and CVE-2026-21852) that enabled remote code execution and API credential theft through malicious project configuration files. The attack surface is the `.claude/settings.json` file that Claude Code reads automatically when a developer opens a project. Three distinct attack vectors were identified: hooks-based RCE via embedded shell commands that execute on every collaborator's machine, MCP ser

Radar Context

Claude Code
Alignment: Challenges current position
Related Positions: AI Governance and Risk, AI-Assisted Development Tooling
Related Partnerships: Anthropic (Claude)
claude-codecvesecurity-vulnerabilityrceapi-key-exfiltrationmcp-securitysupply-chaincheck-point-researchanthropicai-coding-tools-security
Check Point Research: Claude Code CVEs Enable RCE and API Token Exfiltration Through Repository Config Files — Intelligence — Agentic Developer Tools Radar · Signal