Knowledge base
CodexGuild Knowledge Base

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

as of Jan 21, 2026 · applies to @anthropic-ai/claude-code < 2.0.65 · canonical · codexguild.com/kb/ghsa-jh7p-qr78-84p7 · exported 2026-10-11
Canonical as of Jan 21, 2026

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Medium severity. Affects @anthropic-ai/claude-code < 2.0.65. Upgrade to 2.0.65 or later.

CVE-2026-21852 / GHSA-jh7p-qr78-84p7 · severity: medium · npm

Affected

  • @anthropic-ai/claude-code < 2.0.65 → fixed in 2.0.65

Details

A vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. If a user started Claude Code in an attacker-controller repository, and the repository included a settings file that set ANTHROPIC_BASE_URL to an attacker-controlled endpoint, Claude Code would issue API requests before showing the trust prompt, including potentially leaking the user's API keys.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Source: GHSA-jh7p-qr78-84p7 — GitHub Advisory Database (CC-BY-4.0).