Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852
2026-02-28T18:00:18Z•c801cb61d4e0c3afbb7e2f17fd293c760d957bdcbf96c6270990173992f61ed4
CVE-2025-59536CVE-2026-21852API token exfiltrationAnthropicClaude CodeMCPModel Context ProtocolRCEcredential theftenvironment variablesexploithooksproject configurationremote code executionsupply chainvulnerability disclosure
What happened
Check Point Research disclosed critical vulnerabilities in Anthropic’s Claude Code that allow remote code execution and exfiltration of API credentials via malicious project configuration files. The flaws abuse project Hooks, Model Context Protocol (MCP) servers, and environment-variable handling to run arbitrary shell commands and steal tokens/credentials from developer environments, potentially enabling supply-chain, lateral-movement, or account compromise. Anthropic-assigned CVE identifiers include CVE-2025-59536 and CVE-2026-21852.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- c801cb61d4e0c3afbb7e2f17fd293c760d957bdcbf96c6270990173992f61ed4
- Enrichment time
- 2026-02-28T18:00:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.