Claude vulnerabilities
8 CVEs tracked
During the reporting period, Claude appeared in multiple critical contexts. First, the ClaudeBleed vulnerability allowed malicious Chrome extensions to abuse Claude for Chrome's permissions, while shared conversations and artifacts were found indexed by Google and third-party sites, exposing internal company data, financial models, and API keys. Second, a Chinese threat actor leveraged CVEs such as CVE-2024-21762, CVE-2026-0300, and CVE-2026-25253 to target AI-API resellers like derouter.ai, stealing 775 upstream Claude API keys and associated traffic data. Defenders should educate Claude users about the risks of the share feature, immediately review published artifacts and conversation settings, and revoke any inadvertently exposed API keys.
Azərbaycanca: Hesabat dövründə Claude bir neçə mühüm kontekstdə qeyd olunub. Birincisi, ClaudeBleed adlandırılan zəiflik Chrome genişləndirməsinin sui-istifadəsinə səbəb olub, həmçinin paylaşılan söhbətlər və artifact-lər Google və üçüncü tərəf saytlar tərəfindən indekslənərək şirkət daxili məlumatların, maliyyə modellərinin və API açarlarının açıq qalmasına gətirib çıxarıb. İkincisi, Çin mənşəli təhdid aktyoru CVE-2024-21762, CVE-2026-0300, CVE-2026-21858, CVE-2026-25253, CVE-2026-3055, CVE-2026-33017, CVE-2026-34486, CVE-2026-48168 kimi zəifliklərdən istifadə edərək Claude API açarlarını oğurlamaq məqsədilə derouter.ai kimi resellerləri hədəf alıb. Müdafiəçilər Claude istifadəçilərini paylaşım funksiyalarının riskləri barədə məlumatlandırmalı, xüsusilə artifact və söhbət paylaşım parametrlərini nəzərdən keçirməli və sızan API açarlarını dərhal ləğv etməlidir.
This vendor's CVEs8
This hub is built from skopnix's own reporting on Claude: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.