CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-25725: Claude Code Sandbox Escape

August 27, 2026

A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious .claude/settings.json file with hooks that execute arbitrary commands on the host.