Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2396 articles · 112013 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-34452PATCHED
anthropic · anthropic

Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

Description

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returned the unresolved path for subsequent file operations. A local attacker able to write to the memory directory could retarget a symlink between validation and use, causing reads or writes to escape the sandbox. The synchronous memory tool implementation was not affected. This issue has been patched in version 0.87.0.

Affected Products

VendorProductVersions
anthropicanthropic>= 0.86.0, < 0.87.0

References

  • https://github.com/anthropics/anthropic-sdk-python/security/advisories/GHSA-w828-4qhx-vxx3(x_refsource_CONFIRM)
  • https://github.com/anthropics/anthropic-sdk-python/commit/6599043eee6e86dce16953fcd1fd828052052be6(x_refsource_MISC)
  • https://github.com/anthropics/anthropic-sdk-python/releases/tag/v0.87.0(x_refsource_MISC)
CISA KEV❌ No
Actively exploited❌ No
Patch available
anthropic@0.87.0
CWECWE-59, CWE-367
PublishedMar 31, 2026
Last enriched19d ago
Trending Score0
Source articles0
Independent0
Info Completeness4/14
Missing: vendor, product, versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-35022EXP
Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper
Trending: 46
HIGHCVE-2026-30624
CVE-2026-30624: Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a
Trending: 25
NONECVE-2026-35021
Anthropic Claude Code & Agent SDK OS Command Injection via promptEditor.ts
Trending: 6
NONECVE-2026-35020
Anthropic Claude Code & Agent SDK OS Command Injection via TERMINAL Environment Variable
Trending: 6
HIGHCVE-2026-21852
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before u
Trending: 5

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Discovered by ZDM
Apr 1, 2026
Patch Available
Apr 3, 2026