Incorrect Permission Assignment for Critical Resource Affecting @anthropic-ai/sdk package, versions >=0.79.0 <0.91.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ANTHROPICAISDK-16322960
  • published30 Apr 2026
  • disclosed29 Apr 2026
  • creditlucasfutures

Introduced: 29 Apr 2026

NewCVE-2026-41686  (opens in a new tab)
CWE-732  (opens in a new tab)

How to fix?

Upgrade @anthropic-ai/sdk to version 0.91.1 or higher.

Overview

@anthropic-ai/sdk is a The official TypeScript library for the Anthropic API

Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource in the BetaLocalFilesystemMemoryTool that creates memory files and directories using the Node.js default modes (0o666 for files, 0o777 for directories). An attacker can access persisted agent state. In environments with a permissive umask (e.g. Docker, where umask is often 0o000) the attacker can modify sensitive memory files to influence subsequent model behavior.

CVSS Base Scores

version 4.0
version 3.1