📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h
Vulnerabilities

CVE-2026-35021

High
CWE-78 — Weakness Type
Published: Apr 6, 2026  ·  Modified: Apr 13, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions into file paths that are interpolated into shell commands executed via execSync. Although the file path is wrapped in double quotes, POSIX shell semantics (POSIX §2.2.3) do not prevent command substitution within double quotes, allowing injected expressions to be evaluated and resulting in arbitrary command execution with the privileges of the user running the CLI.

🤖 AI Executive Summary

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows arbitrary command execution through malicious file paths. Attackers can inject shell metacharacters into file paths that bypass double-quote protections due to POSIX shell command substitution semantics.

📄 Description (Arabic)

تحتوي أداة استدعاء محرر الموجهات في Anthropic Claude على ثغرة حقن أوامر تسمح بتنفيذ أوامر تعسفية. يمكن للمهاجمين استخدام أحرف metacharacters مثل $() والتعبيرات backtick في مسارات الملفات لتجاوز الحماية. الثغرة تؤثر على أي مستخدم يقوم بتشغيل CLI مع ملفات غير موثوقة.

🤖 ملخص تنفيذي (AI)

مجموعة أدوات Anthropic Claude Code CLI و Claude Agent SDK تحتوي على ثغرة حقن أوامر نظام التشغيل في أداة استدعاء محرر الموجهات. يمكن للمهاجمين تنفيذ أوامر تعسفية من خلال مسارات ملفات ضارة تتجاوز حماية علامات الاقتباس المزدوجة.

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 01:00
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government telecom banking healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
8.0
/ 10.0
🔧 Remediation Steps (English)
Update Anthropic Claude Code CLI and Claude Agent SDK to the latest patched version immediately. Implement input validation and sanitization for all file paths before shell execution. Use parameterized command execution methods instead of string interpolation with execSync. Apply principle of least privilege to CLI user accounts. Monitor for suspicious file path patterns in logs.
🔧 خطوات المعالجة (العربية)
قم بتحديث Anthropic Claude Code CLI و Claude Agent SDK إلى أحدث إصدار مصحح فوراً. قم بتطبيق التحقق من صحة المدخلات وتنظيف جميع مسارات الملفات قبل تنفيذ الأوامر. استخدم طرق تنفيذ الأوامر المعاملة بدلاً من الاستيفاء النصي مع execSync. طبق مبدأ الامتيازات الأقل على حسابات مستخدمي CLI. راقب أنماط مسارات الملفات المريبة في السجلات.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
CC-6.1 CC-6.2 CC-7.2
🟡 ISO 27001:2022
A.12.2.1 A.14.2.1 A.14.2.5
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-78
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-04-06
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-78
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.