{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/checkpoint-claude-code-project-files-cves-2026/",
 "asOf": "2026-09-26",
 "id": "checkpoint-claude-code-project-files-cves-2026",
 "date": "2026-02-25",
 "datePrecision": "day",
 "title": "Check Point: Claude Code project files could run commands and leak API keys before trust prompt",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Check Point Research found that a cloned repository's Claude Code configuration could run hooks, start MCP servers before the user approved them, and redirect API traffic so the user's Anthropic API key was sent to an attacker (CVE-2025-59536, CVE-2026-21852). Anthropic fixed the issues between August and December 2025 by deferring execution and API calls until after the trust dialog.",
 "whyItMatters": "Repository-level agent configuration is executable attack surface that triggers when a developer simply opens a project.",
 "actors": [
  "check-point",
  "anthropic"
 ],
 "topics": [
  "agent-supply-chain",
  "tool-and-mcp-security"
 ],
 "atlas": [
  "supply-chain",
  "credentials",
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/",
   "publisher": "Check Point Research",
   "title": "Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files",
   "date": "2026-02-25",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Hooks issue reported 2025-07-21 and fixed 2025-08-26 (advisory GHSA-ph6w-f82w-28w6); MCP consent bypass reported 2025-09-03, fixed 2025-09-22, CVE-2025-59536 published 2025-10-03; API-key exfiltration reported 2025-10-28, fixed 2025-12-28, CVE-2026-21852 published 2026-01-21.",
   "locator": "Timeline and Disclosure"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "agent-data-exfiltration",
  "approval-bypass",
  "credential-overreach",
  "human-approval",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}