CVE-2026-35022 | Anthropic Claude Code/Claude Agent SDK for Python os command injection (EUVD-2026-19442)
A vulnerability described as critical has been identified in Anthropic Claude Code and Claude Agent SDK for Python. This affects an unknown part. Executing a manipulation of the argument apiKeyHelper/awsAuthRefresh/awsCredentialExport/gcpAuthRefresh can lead to os command injection.
The identification of this vulnerability is CVE-2026-35022. The attack may be launched remotely. There is no exploit available.