CVE-2026-25725 | Anthropic claude-code up to 2.1.1 Bubblewrap Sandboxing .claude/settings.json trust boundary violation (GHSA-ff64-7w26-62rf / Nessus ID 305986)
A vulnerability classified as critical has been found in Anthropic claude-code up to 2.1.1. This impacts an unknown function of the file .claude/settings.json of the component Bubblewrap Sandboxing. This manipulation causes trust boundary violation.
The identification of this vulnerability is CVE-2026-25725. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.