Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security ToolsMeta_SecAlign(01.10.2026 um 02:46 Uhr)
•••
IT Security NachrichtenAlphabet Aktie: Gemini 4 Argon startet - Börse Express(01.10.2026 um 01:57 Uhr)
••••
Sichere Programmierung[$] LWN.net Weekly Edition for October 1, 2026(01.10.2026 um 02:30 Uhr)
•
KI & AI VideosJulian Goldie SEO: Gemini 4 Argon just dropped!(01.10.2026 um 02:45 Uhr)
•
KI & AI VideosJulian Goldie SEO: Gemini 4 Argon!(01.10.2026 um 02:48 Uhr)
•
IT Security ToolsMeta_SecAlign(01.10.2026 um 02:46 Uhr)
•••
IT Security NachrichtenAlphabet Aktie: Gemini 4 Argon startet - Börse Express(01.10.2026 um 01:57 Uhr)
••••
Sichere Programmierung[$] LWN.net Weekly Edition for October 1, 2026(01.10.2026 um 02:30 Uhr)
•
KI & AI VideosJulian Goldie SEO: Gemini 4 Argon just dropped!(01.10.2026 um 02:45 Uhr)
•
KI & AI VideosJulian Goldie SEO: Gemini 4 Argon!(01.10.2026 um 02:48 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

CVE-2026-21852: Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission

Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission Vulnerability ID: CVE-2026-21852 CVSS Score: 5.3 Published: 2026-01-21 A…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!




Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission




Vulnerability ID: CVE-2026-21852

CVSS Score: 5.3

Published: 2026-01-21




A critical logic flaw in Anthropic's Claude Code CLI tool allowed malicious repositories to exfiltrate user API keys during the initialization phase, specifically occurring before the 'Workspace Trust' prompt was displayed to the user.






TL;DR



The claude-code CLI tool (versions prior to 0.2.x/1.0.0) initialized its network configuration and performed a background API handshake before asking the user if they trusted the current repository. By including a malicious .claudecode/settings.json file in a repository, an attacker could redirect this handshake—containing the user's ANTHROPIC_API_KEY—to an attacker-controlled server. This happened immediately upon running the claude command, rendering the subsequent security prompt useless.









⚠️ Exploit Status: POC






Technical Details





  • CWE ID: CWE-200 (Exposure of Sensitive Information)


  • Attack Vector: Network (AV:N) - via malicious repository config


  • CVSS: 5.3 (Medium)


  • Impact: Confidentiality Loss (API Key Exfiltration)


  • Exploit Status: PoC Available / Trivial


  • Required Interaction: User must run CLI in malicious dir






Affected Systems




  • Anthropic Claude Code CLI (< 0.2.x)

  • Developer Workstations

  • CI/CD Pipelines using Claude Code


  • claude-code: < 0.2.29 (Fixed in: 1.0.0)






Code Analysis






Commit: e4f8a9c



Fix: Move workspace trust check before config loading and network initialization




@@ -15,6 +15,7 @@
+ await ensureWorkspaceTrusted();
const config = loadConfig();
- await ensureWorkspaceTrusted();









Exploit Details





  • GitHub: Proof of Concept repository demonstrating API key exfiltration via settings.json






Mitigation Strategies




  • Mandatory Trust Gating: Ensure configuration parsing happens after user consent.

  • Input Sanitization: Validate URLs in configuration files against allowlists if possible.

  • Network Isolation: Run untrusted CLI tools in ephemeral containers or sandboxes.



Remediation Steps:




  1. Upgrade claude-code to version 1.0.0 or later immediately.

  2. Revoke and rotate any Anthropic API keys used with previous versions of the CLI.

  3. Review the .claudecode/ directory in any recently accessed repositories for suspicious settings.json files.






References








Read the full report for CVE-2026-21852 on our website for more details including interactive diagrams and full exploit analysis.

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (1 Indikatoren)
CVE-2026-21852
CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2026-21852
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
HIGH EXPLOITABLE · Index 40/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
Interaktion nötig
Authentifizierung
Nicht erforderlich

3. Compliance, SLA & Vendor Adherence

CISA-SSVC-Triage (vulnrichment)CVE-2026-21852
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-01-21T21:34:19.798222Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
  • Upstream-Referenz (Code-Hosting, kein Advisory)
    github.com
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CVE-2026-21852: Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission

Thematisch verwandte Begriffe: CVE202621852, Premature, Exfiltration, Claude · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag