Claude Code flaw let malicious repos exfiltrate Anthropic API keys (CVE-2026-21852)
A vulnerability in Claude Code's project-load flow before version 2.0.65 allowed an attacker-controlled repository to include a settings file setting ANTHROPIC_BASE_URL to an attacker endpoint, causing Claude Code to issue API requests before the user trust prompt and potentially leak the user's Anthropic API keys. Anthropic patched the issue in version 2.0.65 and delivered it via auto-update.
Disclosed 21 January 2026 · Record updated 13 September 2026
Impact
Users opening an untrusted repository could have their Anthropic API keys and other data sent to an attacker-controlled endpoint before granting trust.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21852
