Anthropic vulnerabilities
3 CVEs tracked
In our reporting, Anthropic primarily appears in the context of AI agent security and supply chain risks. Key topics include a VM sandbox escape flaw in the Claude Cowork product and the leak of Claude Code's source code via npm, tracked under CVE-2025-59536 and CVE-2026-21852, which is being weaponized by threat actors. Defenders should immediately audit npm dependencies, carefully configure permission models for the Claude Tag agent in Slack, and monitor for the Ruflo vulnerability (CVE-2026-59726) that could lead to AI memory poisoning.
Azərbaycanca: Hesabatlarımızda Anthropic, əsasən AI agentlərinin təhlükəsizliyi və təchizat zənciri riskləri kontekstində önə çıxır. Əsas müzakirə mövzuları Claude Cowork məhsulundakı VM-dən qaçış boşluğu və xüsusilə CVE-2025-59536 ilə CVE-2026-21852 altında izlənilən Claude Code mənbə kodunun npm vasitəsilə sızmasıdır. Bu sızma təhlükə aktorlarına kodu təhlil edərək silahlandırmaq imkanı yaradır. Müdafiəçilər npm asılılıqlarını dərhal audit etməli, Slack üçün Claude Tag agentində icazə modellərini konfiqurasiya edərkən diqqətli olmalı, eyni zamanda AI yaddaşının zəhərlənməsinə səbəb ola biləcək Ruflo boşluğunu (CVE-2026-59726) izləməlidirlər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Anthropic: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.