• News/
  • https://www.theregister.com/2026/02/26/clade_code_cves/

Claude's collaboration tools allowed remote code execution

The Register
·
Jessica Lyons
·
Published Feb 26, 2026
·
Updated

Security vulnerabilities in Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for a developer to clone and open an untrustworthy project. Check Point Software researchers found and reported all three flaws to Anthropic, which issued fixes for all and CVEs for two. Still, the bug hunters say, the issues illustrate a worrisome supply chain threat as enterprises incorporate AI coding tools like Claude into their development processes and essentially turn configuration files into a new attack surface. "The ability to execute arbitrary commands through repository-controlled configuration files created severe supply chain risks, where a single malicious commit could compromise any developer working with the affected repository," Check Point researchers Aviv Donenfeld and Oded Vanunu said in a Wednesday report. Anthropic, the AI company that developed Claude Code, did not respond to The Register's requests for comment. The three security vulnerabilities stem from Claude's design, which is intended to make it easier for development teams to collaborate. The AI coding tool enables this by embedding project-level configuration files (.claude/settings.json file) directly within repositories, so that when a developer clones a project, they automatically apply the same settings used by their teammates. Any contributor with commit access can modify these files. Th...

Read full article

Affected Software

1 affected component
Anthropic Claude Code>=1.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security vulnerabilities in Claude Code that enable remote code execution.

2

What security implications are discussed in the article?

The vulnerabilities could allow attackers to execute code on user machines and steal API keys.

3

What software is affected by these vulnerabilities?

The affected software discussed is Anthropic Claude Code.

4

How could attackers exploit these vulnerabilities?

Attackers could inject malicious configurations into repositories, leading to code execution when a developer clones and opens the project.

5

What preventive measures can users take against these vulnerabilities?

Users should verify the trustworthiness of projects before cloning or opening them to avoid potential exploits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203