CVE-2026-7235: Erlichliu Claude-Agent-SDK-Master
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca1747bf. Affected by this vulnerability is an unknown functionality of the file app/api/agent-output/route.ts. The manipulation of the argument outputFile leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
- Erlichliu Claude-Agent-SDK-Master
Published 2026-04-28. Last modified 2026-06-17.