SCA: security update for @anthropic-ai/claude-code (GHSA-5cwg-9f6j-9jvx)

medium Tenable Cloud Security Plugin ID 440609

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the
system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating
directory ownership or access permissions. Because the ProgramData directory is writable by non-
administrative users by default and the ClaudeCode subdirectory was not pre-created or access-restricted,
a low-privileged local user could create this directory and place a malicious configuration file that
would be automatically loaded for any user launching Claude Code on the same machine. Exploiting this
would have required a shared multi-user Windows system and a victim user to launch Claude Code after the
malicious configuration was placed. This issue has been fixed on version 2.1.75. (CVE-2026-35603)

Solution

Update the @anthropic-ai/claude-code library and its related packages to version 2.1.75 or later.

See Also

https://github.com/advisories/GHSA-5cwg-9f6j-9jvx

Plugin Details

Severity: Medium

ID: 440609

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 4/18/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.88

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-35603

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.4

Threat Score: 2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/17/2026

Vulnerability Publication Date: 4/17/2026

Reference Information

CVE: CVE-2026-35603

cwe: CWE-426