VDB
Sign up
MEDIUM

GHSA-jh7p-qr78-84p7

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Quick fix

GHSA-jh7p-qr78-84p7 — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.

npm install @anthropic-ai/claude-code@2.0.65

Details

A vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. If a user started Claude Code in an attacker-controller repository, and the repository included a settings file that set ANTHROPIC_BASE_URL to an attacker-controlled endpoint, Claude Code would issue API requests before showing the trust prompt, including potentially leaking the user's API keys.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@anthropic-ai/claude-code
Introduced in: 0Fixed in: 2.0.65
Fixnpm install @anthropic-ai/claude-code@2.0.65

References