VDB
Sign up

package

npm/@anthropic-ai/claude-code

pkg:npm/%40anthropic-ai/claude-code

MEDIUMnpm
GHSA-4vp2-6q8c-pvq2· CVE-2026-46406

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

Modified: 7/9/2026

HIGHnpm
GHSA-ph6w-f82w-28w6

Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning

Modified: 9/3/2025