CVE-2026-35020: Anthropic Claude Code & Agent SDK OS Command Injection via TERMINAL Environment Variable
Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and outside the threat model of CLI tools.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35020?
The severity of CVE-2026-35020 is rated as high with a score of 8.6.
What does CVE-2026-35020 involve?
CVE-2026-35020 involves OS command injection via the TERMINAL environment variable in the Anthropic Claude Code & Agent SDK.
Is CVE-2026-35020 currently exploitable?
CVE-2026-35020 has been rejected, indicating that it is not considered exploitable or relevant within its threat model.
What products are affected by CVE-2026-35020?
CVE-2026-35020 affects the Anthropic Claude Code CLI and the Anthropic Claude Agent SDK across various programming languages.
What is the status of CVE-2026-35020?
The status of CVE-2026-35020 is rejected as determined by its CVE Numbering Authority.