China found Security Vulnerabilities in Anthropic’s Claude Code, advised users to uninstall the software or update to its latest version

Reddit r/ArtificialInteligence News

Summary

China announced it found security backdoor vulnerabilities in Anthropic's Claude Code coding tool, warning that certain versions can send user data to remote servers without consent, and advising users to uninstall or update.

China said Wednesday that it has found “security backdoor vulnerabilities” in Anthropic’s popular Claude Code, stepping up tensions in the race with the U.S. for artificial-intelligence supremacy. Several versions of the American coding tool, released between April and June, “can send sensitive information such as user location and identity to remote servers without the user’s consent due to a built-in monitoring mechanism.
Original Article

Similar Articles

Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities

Lobsters Hottest

Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.