CVE-2026-44467
Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development feature verified only whether a hostname existed in ~/.ssh/known_hosts without comparing the server's presented host key against the stored key. This allowed a network-positioned attacker to present an arbitrary SSH host key and have the connection silently accepted, enabling a man-in-the-middle attack on remote development sessions. Successful exploitation required the attacker to be in a network position to intercept SSH traffic (e.g., via ARP spoofing, rogue Wi-Fi, or DNS poisoning) and the target hostname to already have an entry in the victim's known_hosts file. This vulnerability is fixed in 1.4304.0.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2026-05-06 CVE Reserved
- 2026-05-13 CVE Published
- 2026-05-14 CVE Updated
- 2026-05-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-297: Improper Validation of Certificate with Host Mismatch
- CWE-322: Key Exchange without Entity Authentication
CAPEC
References (1)
| URL | Tag | Source |
|---|---|---|
| https://github.com/anthropics/claude-code/security/advisories/GHSA-3rwf-2g6p-c2f9 | X_refsource_confirm |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Anthropics Search vendor "Anthropics" | Claude-code Search vendor "Anthropics" for product "Claude-code" | >= 1.2581.0 < 1.4304.0 Search vendor "Anthropics" for product "Claude-code" and version " >= 1.2581.0 < 1.4304.0" | en |
Affected
| ||||||
