SCA: security update for @anthropic-ai/sdk (GHSA-p7fg-763f-g4gf)

medium Tenable Cloud Security Plugin ID 440971

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript
applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in the
Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (0o666 for
files, 0o777 for directories), leaving them world-readable on systems with a standard umask and world-
writable in environments with a permissive umask such as many Docker base images. A local attacker on a
shared host could read persisted agent state, and in containerized deployments could modify memory files
to influence subsequent model behavior. This issue has been patched in version 0.91.1. (CVE-2026-41686)

Solution

Update the @anthropic-ai/sdk library and its related packages to version 0.91.1 or later.

See Also

https://github.com/advisories/GHSA-p7fg-763f-g4gf

Plugin Details

Severity: Medium

ID: 440971

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 4/30/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.71

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.2

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-41686

CVSS v3

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Threat Score: 1.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/29/2026

Vulnerability Publication Date: 4/29/2026

Reference Information

CVE: CVE-2026-41686

cwe: CWE-732