Security researchers have identified vulnerabilities in Claude Code that enable remote code execution and API key exfiltration attacks. The flaws reportedly allow threat actors to execute arbitrary code and steal sensitive authentication credentials from affected systems. Anthropic has not yet publicly commented on the severity or mitigation status of these disclosed vulnerabilities.