Claude Code Malicious Repository Data Exfiltration Vulnerability

Vulnerability

A vulnerability in Claude Code's project-loading process allowed malicious repositories to exfiltrate sensitive data, including Anthropic API keys, before users had a chance to confirm trust. If a user opened Claude Code in a repository controlled by an attacker, and that repository contained a settings file directing API requests to an attacker-controlled endpoint, the application would send out API requests immediately, potentially leaking the user's API keys. This issue affected versions of Claude Code prior to 2.0.65.

Impact

Exploitation of this vulnerability could lead to unauthorized access to a user's Anthropic API keys, allowing an attacker to make API requests on behalf of the user.

Remediation

Users on standard Claude Code auto-update have already received the patch. Those performing manual updates should upgrade to version 2.0.65 or the latest version.

Added: Jan 21, 2026, 9:21 PM
Updated: Jan 21, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.