PulseAugur
EN
LIVE 18:06:47

Claude Code Windows Config Vulnerability Patched by Anthropic

A security vulnerability, CVE-2026-35603, has been identified in Claude Code on Windows, allowing local users to potentially execute arbitrary code. The issue stemmed from Claude Code loading its configuration file from a world-writable folder, enabling a standard user to place a malicious configuration that would run with the privileges of the next user launching the application. Anthropic has since patched the vulnerability in version 2.1.75 by moving the configuration to a protected directory. AI

IMPACT This vulnerability highlights the need for rigorous security practices in AI tooling, especially on shared systems.

RANK_REASON This is a security vulnerability fix for a specific software product, not a frontier release or significant industry event.

Read on dev.to — Claude Code tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Claude Code Windows Config Vulnerability Patched by Anthropic

How we ranked this

Signal score
27 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
This is a security vulnerability fix for a specific software product, not a frontier release or significant industry event.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Ramdai Bista ·

    Claude Code Loaded Windows Config From a World-Writable Folder — CVE-2026-35603

    <p>Not every entry in this database is a critical data-loss story. This one is a Moderate-severity, already-patched CVE — worth documenting precisely because the corpus should reflect the full range, not just the worst incidents.</p> <h2> What happened </h2> <p>Security researche…