Check Point Research: CVE-2026-21852 — RCE and API Token Exfiltration via Claude Code Project Files
Check Point Research·high signal
Check Point Research disclosed two CVEs (CVE-2025-59536, CVE-2026-21852) showing how malicious Claude Code project configuration files can trigger remote code execution and exfiltrate API tokens. The attack abuses Claude Code's hook execution model — untrusted CLAUDE.md files in project directories can inject arbitrary shell commands into the agent lifecycle. This confirms the 'coding agent project configuration attack' vector at full severity against the most widely-used AI coding agent.