CVE-2026-35021: Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts
Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35021?
CVE-2026-35021 is considered a critical severity vulnerability due to its ability to allow arbitrary OS command execution.
How do I fix CVE-2026-35021?
To fix CVE-2026-35021, update to the latest version of the Anthropic Claude Code CLI and Claude Agent SDK that addresses this OS command injection vulnerability.
What does CVE-2026-35021 impact?
CVE-2026-35021 impacts the Anthropic Claude Code CLI and Claude Agent SDK by allowing command injection through a vulnerable prompt editor utility.
What are the potential consequences of CVE-2026-35021?
The potential consequences of CVE-2026-35021 include unauthorized access, data theft, and system compromise due to arbitrary command execution.
Who is affected by CVE-2026-35021?
Users and organizations utilizing the Anthropic Claude Code CLI and Claude Agent SDK are affected by CVE-2026-35021.