A security vulnerability, CVE-2026-35603, has been identified in Claude Code on Windows, allowing local users to potentially execute arbitrary code. The issue stemmed from Claude Code loading its configuration file from a world-writable folder, enabling a standard user to place a malicious configuration that would run with the privileges of the next user launching the application. Anthropic has since patched the vulnerability in version 2.1.75 by moving the configuration to a protected directory. AI
IMPACT This vulnerability highlights the need for rigorous security practices in AI tooling, especially on shared systems.
RANK_REASON This is a security vulnerability fix for a specific software product, not a frontier release or significant industry event.
Read on dev.to — Claude Code tag →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →