Check Point CVE-2025-59536 / CVE-2026-21852: Untrusted Repo .claude/settings.json Enables RCE and Anthropic API Key Exfiltration via Hooks
Check Point Research·high signal
Check Point Research disclosed that Claude Code's .claude/settings.json hooks can be weaponized in untrusted repos to execute arbitrary shell commands (CVE-2025-59536) and exfiltrate Anthropic API keys by redirecting ANTHROPIC_BASE_URL to an attacker-controlled MitM proxy (CVE-2026-21852). Both CVEs are patched, but the attack surface — project-level config files that execute before the user grants trust — applies broadly to any hook-enabled agentic IDE. Never open unreviewed repos with AI coding tools without inspecting their .claude/ or equivalent config directories first.