Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. Attackers who can influence authentication settings can inject shell metacharacters through parameters like apiKeyHelper, awsAuthRefresh, awsCredentialExport, and gcpAuthRefresh to execute arbitrary commands with the privileges of the user or automation environment, enabling credential theft and environment variable exfiltration.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-35022 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag behavior is documented in Anthropic's claude -h output with an explicit warning that non-interactive mode should only be used in trusted directories, making this intended and described behavior rather than a vulnerability.
CVE-2026-35022
- High severity, but no confirmed exploitation yet
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
- CVSS v3
- 9.8
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0.6%
- EPSS %ILE
- 69th
- KEV
- Not listed
Published
April 6, 2026
Last Modified
April 29, 2026
Advisory Details (2)
Auto-updated Oct 8, 2026Claude Code CLI: 3 Command Injection Flaws — CI/CD Risk
https://phoenix.security/critical-ci-cd-nightmare-3-command-injection-flaws-in-claude-code-cli-allow-credential-exfiltration/Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper | Advisories | VulnCheck
https://www.vulncheck.com/advisories/anthropic-claude-code-agent-sdk-os-command-injection-via-authentication-helperWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 0× in last 7d / 1× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-21 12:19 UTCOSV refresh
- 2026-09-02 09:44 UTCOSV refresh
- 2026-08-16 08:22 UTCGHSA enrichment
- 2026-08-12 19:44 UTCGHSA enrichment
- 2026-08-09 05:01 UTCGHSA enrichment
- 2026-08-06 00:06 UTCGHSA enrichment
- 2026-08-02 14:22 UTCEG score recompute
- 2026-08-02 14:22 UTCGHSA enrichment
- 2026-07-23 03:10 UTCEG score recompute▼ 9.80
- 2026-07-17 16:59 UTCOSV refresh
- 2026-06-12 05:02 UTCGHSA enrichment
- 2026-06-12 01:18 UTCGHSA enrichment
- 2026-06-11 21:33 UTCGHSA enrichment
- 2026-06-10 20:28 UTCGHSA enrichment
- 2026-06-10 16:44 UTCGHSA enrichment
- 2026-06-10 12:59 UTCGHSA enrichment
- 2026-06-10 08:41 UTCGHSA enrichment
- 2026-06-10 04:57 UTCGHSA enrichment
- 2026-06-10 01:12 UTCGHSA enrichment
- 2026-06-09 17:48 UTCGHSA enrichment
- 2026-06-09 14:04 UTCGHSA enrichment
- 2026-06-08 12:52 UTCGHSA enrichment
- 2026-06-08 09:08 UTCGHSA enrichment
- 2026-06-08 05:17 UTCGHSA enrichment
- 2026-06-08 01:32 UTCGHSA enrichment
Show 29 moreShow fewer
- 2026-06-07 21:47 UTCGHSA enrichment
- 2026-06-07 18:02 UTCGHSA enrichment
- 2026-06-07 14:17 UTCGHSA enrichment
- 2026-06-07 10:27 UTCGHSA enrichment
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-26 13:44 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-20 22:38 UTCEPSS rescore
- 2026-05-20 22:38 UTCEPSS rescore
- 2026-05-20 11:22 UTCEPSS rescore
- 2026-05-20 11:22 UTCEPSS rescore
- 2026-05-20 09:37 UTCGHSA enrichment
- 2026-05-20 05:22 UTCGHSA enrichment
- 2026-05-20 01:32 UTCGHSA enrichment
- 2026-05-19 21:29 UTCGHSA enrichment
- 2026-05-19 17:15 UTCGHSA enrichment
- 2026-05-19 13:04 UTCGHSA enrichment
- 2026-05-19 08:45 UTCGHSA enrichment
- 2026-05-19 05:00 UTCGHSA enrichment
- 2026-05-19 01:15 UTCEG score recompute
- 2026-05-19 01:15 UTCGHSA enrichment
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-35022?
When was CVE-2026-35022 disclosed?
Is CVE-2026-35022 actively exploited?
What is the CVSS score of CVE-2026-35022?
How do I remediate CVE-2026-35022?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-35022
Is Your Infrastructure Affected by CVE-2026-35022?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.