CVE-2026-25725

CVSS 10.0 · CRITICAL
EPSS p7
Lower risk — in the top 93% least-likely-to-be-exploited CVEs.
No patch reference
No patch/mitigation in references

Published 2/6/2026 · updated 2/9/2026 · CWE-501, CWE-668

Share
Get asset-aware triage

Summary

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was mounted as writable and .claude/settings.local.json was explicitly protected with read-only constraints, settings.json was not protected if it was missing. This allowed malicious code running inside the sandbox to create this file and inject persistent hooks (such as SessionStart commands) that would execute with host privileges when Claude Code was restarted. This issue has been patched in version 2.1.2.

CVSS 10.0CRITICAL

10.0 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS exploitation probability

0.0%

Percentile p7 Lower risk — in the top 93% least-likely-to-be-exploited CVEs.

Affected products

1 vendor/product entries
  • Anthropic Claude Code< 2.1.2
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Feb 6, 2026 · Disclosed / published in NVD
  2. Feb 9, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 59 days ago
  • CVE.org· no data
  • FIRST EPSS· 59 days ago
  • CISA KEV· no data
  • OSV· no data

References

Unlock the full report

See how CVE-2026-25725 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.