The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @anthropic-ai/claude-code to version 2.1.260 or higher.
@anthropic-ai/claude-code is an Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.
Affected versions of this package are vulnerable to Incorrect Behavior Order via incorrect API key selection during server-managed settings retrieval. When a session authenticates with a Claude Enterprise or Team account, the settings fetch logic incorrectly prioritizes a locally stored API key (from a prior /login or direct configuration write) over the authenticated session credentials. When the settings endpoint rejects that stored key, the session starts without the organization's server-managed policy - including permission deny rules, model restrictions, and managed-only locks - or, if a previously cached copy exists on the machine, continues applying that stale copy without receiving later policy changes, while still operating as the organization's account. Endpoint-managed (MDM or file-based) settings are not affected.
Note: This is only exploitable with local access to a device that has a stored API key; the no-policy case additionally requires that no managed settings have previously been cached on that device.