CVE-2026-34450: The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
Summary
The Claude SDK for Python (a library that lets Python programs use Claude AI) had a security flaw in versions 0.86.0 through 0.87.0 where memory files were created with overly permissive access controls (mode 0o666, meaning world-readable and world-writable permissions). On shared computers or in Docker containers, attackers could read the stored state of AI agents or modify memory files to change how the model behaves.
Solution / Mitigation
This issue has been patched in version 0.87.0. Update the Claude SDK for Python to version 0.87.0 or later.
Vulnerability Details
EPSS: 0.0%
March 31, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34450
First tracked: March 31, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 95%