SB2026043037 - Multiple vulnerabilities in Claude Code
Published: April 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-24052)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the trusted domain verification mechanism for WebFetch requests when validating trusted domains. A remote attacker can register or use a crafted domain name that passes validation to disclose sensitive information.
User interaction is required.
2) Code Injection (CVE-ID: CVE-2025-59536)
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the startup trust dialog implementation when opening Claude Code in an untrusted directory. A remote attacker can trick the user into starting Claude Code in a crafted project directory to execute arbitrary code.
User interaction is required to start Claude Code in an untrusted directory.
Remediation
Install update from vendor's website.