Claude Code Token Compromise & Hook Hijacking: Auditing CVE-2026-21852, Base URL Redirection, and the Pre-Trust Execution Surface
A technical audit of Anthropic’s Claude Code vulnerabilities CVE-2026-21852 and CVE-2025-59536. We dissect pre-trust Base URL credential exfiltration, SessionStart hook code execution, Linux plaintext token leakage, and introduce a 4-tier eBPF zero-trust isolation blueprint.