A vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. If a user started Claude Code in an attacker-controller repository, and the repository included a settings file that set ANTHROPICBASEURL to an attacker-controlled endpoint, Claude Code would issue API requests before showing the trust prompt, including potentially leaking the user's API keys.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
{
"github_reviewed_at": "2026-01-21T01:00:31Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-522"
],
"github_reviewed": true,
"nvd_published_at": "2026-01-21T21:16:08Z"
}