CVE Explorer
CVE-2026-34451
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not append a trailing path separator. A model steered by prompt injection could supply a crafted path that resolved to a sibling directory sharing the memory root's name as a prefix, allowing reads and wri
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-41","description":"CWE-41: Improper Resolution of Path Equivalence","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"anthropic-sdk-typescript","vendor":"anthropics","versions":[{"status":"affected","version":">= 0.79.0, < 0.81.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-41","description":"CWE-41: Improper Resolution of Path Equivalence","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/anthropics/anthropic-sdk-typescript/commit/0ac69b3438ee9c96b21a7d3c39c07b7cdb6995d9","tags":["x_refsource_MISC"],"url":"https://github.com/anthropics/anthropic-sdk-typescript/commit/0ac69b3438ee9c96b21a7d3c39c07b7cdb6995d9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/references/1
{"name":"https://github.com/anthropics/anthropic-sdk-typescript/releases/tag/sdk-v0.81.0","tags":["x_refsource_MISC"],"url":"https://github.com/anthropics/anthropic-sdk-typescript/releases/tag/sdk-v0.81.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/references/2
{"name":"https://github.com/anthropics/anthropic-sdk-typescript/security/advisories/GHSA-5474-4w2j-mq4c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/anthropics/anthropic-sdk-typescript/security/advisories/GHSA-5474-4w2j-mq4c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d079b1673867c78a7b8b3c992b858f99219c67abb883cdd7ccb3b03d6f83dd73 · sha256:87e95947c09e9880… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.