AI/ML, Vulnerability Management, Patch/Configuration Management

RCE, API credential theft likely with now-patched Claude Code vulnerabilities

(Adobe Stock)

The Hacker News reports that Anthropic's Claude Code has been impacted by a trio of now-addressed security flaws, which could have been harnessed to enable remote code execution and API credential compromise.

Multiple configuration mechanisms, including Model Context Protocol servers, Hooks, and environment variables, have been leveraged by a pair of high-severity code injection vulnerabilities and a medium-severity information disclosure issue to execute arbitrary commands and pilfer data, respectively, findings from Check Point Research analysts revealed.

Threat actors could exploit one of the high-severity bugs, tracked as CVE-2025-59536, to dismiss explicit user approval before external tool and service interactions via MCP. Integration of command execution and autonomous network communication capabilities into AI-powered tools prompts significant threat model changes, noted researchers.

"The risk is no longer limited to running untrusted code it now extends to opening untrusted projects. In AI-driven development environments, the supply chain begins not only with source code, but with the automation layers surrounding it," they added.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds