{"data":{"ecosystem":"npm","name":"@anthropic-ai/sdk","url":"https://aisecwatch.com/packages/npm/@anthropic-ai/sdk","latestVersion":"0.133.0","firstReleaseAt":"2023-01-31T15:44:00.296Z","repository":"https://github.com/anthropics/anthropic-sdk-typescript","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-01-31T15:44:00.296Z","integratedVersion":"0.2.0","sdks":["anthropic"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"npm","name":"json-schema-to-ts","versionSpec":"^3.1.1","scope":"runtime"},{"ecosystem":"npm","name":"standardwebhooks","versionSpec":"^1.0.0","scope":"runtime"}],"advisories":[{"id":"b83d9f7b-74a7-4bf5-8e8a-d4c09def461a","url":"https://aisecwatch.com/issues/b83d9f7b-74a7-4bf5-8e8a-d4c09def461a","cveId":"CVE-2026-41686","title":"GHSA-p7fg-763f-g4gf: Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool","severity":"medium","publishedAt":"2026-04-29T22:28:12.000Z","affected":["@anthropic-ai/sdk@>= 0.79.0, < 0.91.1 (fixed: 0.91.1)"],"epssScore":0.00126}],"checkedAt":"2026-10-09T21:51:58.245Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}