Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852

2026-02-28T18:00:18Zc801cb61d4e0c3afbb7e2f17fd293c760d957bdcbf96c6270990173992f61ed4
CVE-2025-59536CVE-2026-21852API token exfiltrationAnthropicClaude CodeMCPModel Context ProtocolRCEcredential theftenvironment variablesexploithooksproject configurationremote code executionsupply chainvulnerability disclosure

What happened

Check Point Research disclosed critical vulnerabilities in Anthropic’s Claude Code that allow remote code execution and exfiltration of API credentials via malicious project configuration files. The flaws abuse project Hooks, Model Context Protocol (MCP) servers, and environment-variable handling to run arbitrary shell commands and steal tokens/credentials from developer environments, potentially enabling supply-chain, lateral-movement, or account compromise. Anthropic-assigned CVE identifiers include CVE-2025-59536 and CVE-2026-21852.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
c801cb61d4e0c3afbb7e2f17fd293c760d957bdcbf96c6270990173992f61ed4
Enrichment time
2026-02-28T18:00:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.