PulseAugur
实时 18:06:53
English(EN) Claude Code Loaded Windows Config From a World-Writable Folder — CVE-2026-35603

Anthropic 修补了 Claude Code Windows 配置漏洞

Claude Code on Windows 中已发现一个安全漏洞 CVE-2026-35603,可能允许本地用户执行任意代码。该问题源于 Claude Code 从一个可被所有人写入的文件夹加载其配置文件,使得普通用户可以放置一个恶意配置文件,该文件将在下一个启动该应用程序的用户特权下运行。Anthropic 已在 2.1.75 版本中通过将配置移至受保护的目录来修补了此漏洞。 AI

影响 此漏洞凸显了在 AI 工具中实施严格安全实践的必要性,尤其是在共享系统上。

排序理由 这是一个针对特定软件产品的安全漏洞修复,而非前沿发布或重大的行业事件。

在 dev.to — Claude Code tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Anthropic 修补了 Claude Code Windows 配置漏洞

本文如何被排名

Signal score
27 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
这是一个针对特定软件产品的安全漏洞修复,而非前沿发布或重大的行业事件。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Ramdai Bista ·

    Claude Code 从可写入的文件夹加载 Windows 配置 — CVE-2026-35603

    <p>Not every entry in this database is a critical data-loss story. This one is a Moderate-severity, already-patched CVE — worth documenting precisely because the corpus should reflect the full range, not just the worst incidents.</p> <h2> What happened </h2> <p>Security researche…