Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Yes—the security story is real, but “just open a malicious project” is shorthand. The documented attacks generally required launching Claude Code in, or directing it at, an untrusted repository. Check Point Research and NVD records describe flaws that let repository-controlled settings run shell commands, redirect API traffic, weaken permission checks, or bypass trust decisions in specific Claude Code versions. Downloading a repository alone did not automatically compromise every computer.
Why a project can control more than source code
Ordinary source files are usually passive until a developer compiles or runs them. An agentic coding tool adds another category: project-local instructions and configuration that can influence hooks, tools, permissions, environment variables, network destinations and MCP integrations.
Claude Code supports project settings in files such as .claude/settings.json. Check Point Research reported that repository-controlled settings could define hooks and other behavior. That makes a dotfile part of the execution surface, even though it looks like data rather than a program. The broader supply-chain lesson is that documentation, Git metadata and agent configuration deserve the same suspicion as build scripts and package-install hooks. Check Point’s technical analysis
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWhat Claude Code’s trust prompt was meant to protect
- The user starts Claude Code in a directory or points it at a repository.
- The client determines whether that directory is trusted.
- A trust prompt asks the user to approve project-local behavior.
- Configuration, hooks and other potentially dangerous actions should be subject to that decision.
Anthropic’s postmortem describes the affected class as activity occurring before the trust dialog. In the disclosed bugs, project-controlled input could be parsed or acted on before meaningful consent had been established. The issue was therefore not simply that Claude might follow hostile text in a README; some startup paths connected repository data to commands or network behavior first. Anthropic’s explanation of the trust-boundary failures
#1 Best Overall
The two findings that started the warning
CVE-2025-59536: commands before trust
Check Point Research reported that a malicious project could place a hook in .claude/settings.json. Starting Claude Code in that project could execute the hook before the trust decision was properly enforced, potentially allowing arbitrary shell commands or a reverse shell. This is materially different from a prompt-injection attempt that merely asks the model to do something.
Versions before 1.0.111 were affected. Anthropic’s normal auto-update path was intended to distribute the fix; users on manual installations had to update themselves. The NVD record documents the affected range and remediation. NVD: CVE-2025-59536
CVE-2026-21852: API endpoint redirection
A separate flaw affected versions before 2.0.65. A repository could set ANTHROPIC_BASE_URL to an attacker-controlled endpoint. Claude Code could then send API requests there before trust confirmation, potentially exposing the Anthropic API key.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →The consequences depend on that key’s permissions and the services it can reach. A stolen credential could enable access to shared workspace data, changes or deletion, unwanted uploads, or unexpected API charges. Those are possible downstream effects, not proof that every account would suffer all of them. NVD: CVE-2026-21852
Rank #3
The trust-boundary problem continued in later releases
Updating only for the original 2025 report is not enough. Subsequent disclosures affected different versions and attack paths. Each entry below has its own prerequisites; no single row means every release was vulnerable to every technique.
| Vulnerability | Affected versions | Fixed version | Core issue |
|---|---|---|---|
| CVE-2025-59536 | Before 1.0.111 | 1.0.111 | Code execution before trust confirmation |
| CVE-2026-21852 | Before 2.0.65 | 2.0.65 | API endpoint redirection and possible key exposure |
| CVE-2026-33068 | Before 2.1.53 | 2.1.53 | Repository-controlled selection of bypassPermissions |
| CVE-2026-40068 | 2.1.63–2.1.83 | 2.1.84 | Malicious Git worktree commondir causing trust confusion |
| CVE-2026-54316 | 0.2.54–2.1.162 | 2.1.163 | Exfiltration through attacker-controlled WebFetch behavior |
| CVE-2026-55607 | 2.1.38–2.1.162 | 2.1.163 | Symlink and Git fsmonitor behavior enabling file overwrite and code execution under specific conditions |
See the individual NVD records for CVE-2026-33068, CVE-2026-40068, CVE-2026-54316 and CVE-2026-55607.
Rank #4
Is an updated Claude Code safe enough?
Install current updates through Claude Code’s normal mechanism. Anthropic documents the claude update command for manual updates and says the tool normally keeps itself updated. Confirm the installed version afterward, and check Anthropic’s security advisories before relying on any version as current because releases and fixes change. Anthropic support documentation
A patch closes known defects; it does not make an arbitrary repository trustworthy. Package lifecycle scripts, Git hooks, build tools, editor extensions and future undiscovered bugs remain relevant. Sandboxing also is not a complete answer if the client’s filesystem or Git integration has its own weakness.
Best Value
A safer workflow for an unfamiliar repository
- Update before inspection. Do not use an old Claude Code installation to examine unknown code.
- Keep Claude Code out initially. Clone the repository without launching the agent in it.
- Review control files manually. Check
.claude/settings.json,CLAUDE.md, MCP configuration, hooks, shell scripts, Git worktree metadata, package-manager lifecycle scripts, Docker files, Makefiles, task runners and CI configuration. - Search for redirection and credential access. Look for
ANTHROPIC_BASE_URL, proxy settings, curl or wget commands, and references to environment variables, tokens and credential stores. - Use an ephemeral environment. Prefer a disposable VM or container with no personal SSH keys, cloud credentials, browser profile, password store or production token. Do not grant host sockets or privileged access merely because a container is being used.
- Use least privilege. If an API key is necessary, make it short-lived, narrowly scoped and subject to spending limits.
- Restrict networking. Keep initial inspection offline or behind controlled egress where practical.
- Review every permission prompt. Never enable a permissive mode such as bypassing permissions for an unknown project.
- Monitor activity. Watch API usage, workspace changes, uploads and billing for anomalies.
- Destroy the environment afterward. Deleting a disposable VM is safer than trying to clean a workstation that may have executed hostile code.
These controls reduce exposure; none guarantees safety.
If Claude Code already ran on a suspicious project
- Disconnect or isolate the machine from sensitive networks.
- Revoke and rotate Anthropic keys plus credentials in environment variables, shell profiles, SSH agents, cloud CLIs, package registries and local files.
- Inspect shell startup files, scheduled tasks, launch agents, Git hooks and recently modified files.
- Review Anthropic usage, workspace and billing activity, then check GitHub, cloud, registry and CI/CD logs.
- Preserve evidence before deleting the repository if investigation may be required.
- Rebuild the machine when there is evidence of arbitrary code execution and it held valuable credentials.
- Notify your security team or incident-response provider.
Rotating only the Anthropic key is insufficient if the vulnerable path may have achieved host-level execution.
What organizations should enforce
- Centralized version enforcement and rapid patch deployment.
- Approved project configuration and review of hooks and MCP servers.
- Ephemeral developer environments with no standing production credentials.
- Network egress controls that prevent unknown endpoints from receiving agent traffic.
- Short-lived, least-privilege API keys with budget alerts and rapid revocation.
- Audit logs covering agent launches, tool calls, file changes, network requests and credential use.
- Repository and dependency scanning as a complementary layer, not a substitute for endpoint isolation.
Bottom line
The vulnerabilities were real, but the accurate lesson is narrower than the headline: launching Claude Code against an untrusted repository made initialization part of the security boundary. Update the client, inspect project-local instructions as hostile input, isolate the environment and keep credentials disposable. Do not treat a trust prompt—or a patched client—as proof that unknown code is safe.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

