CVE-2026-25723
- EPSS 0.26%
- Veröffentlicht 06.02.2026 18:15:59
- Zuletzt bearbeitet 09.02.2026 14:50:15
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file write restrictions. This vulnerability enabled writin...
CVE-2026-25722
- EPSS 0.36%
- Veröffentlicht 06.02.2026 18:15:59
- Zuletzt bearbeitet 09.02.2026 14:51:42
Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate into sensitive directories like .c...
CVE-2026-24887
- EPSS 0.56%
- Veröffentlicht 03.02.2026 20:50:25
- Zuletzt bearbeitet 06.02.2026 20:19:47
Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting...
CVE-2026-24053
- EPSS 0.46%
- Veröffentlicht 03.02.2026 20:49:59
- Zuletzt bearbeitet 06.02.2026 20:24:38
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user p...
CVE-2026-24052
- EPSS 0.34%
- Veröffentlicht 03.02.2026 20:49:41
- Zuletzt bearbeitet 06.02.2026 20:28:53
Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted do...
CVE-2026-21852
- EPSS 22.97%
- Veröffentlicht 21.01.2026 20:42:06
- Zuletzt bearbeitet 02.02.2026 15:04:41
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repos...
CVE-2025-66032
- EPSS 0.63%
- Veröffentlicht 03.12.2025 18:16:54
- Zuletzt bearbeitet 05.12.2025 16:29:42
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploit...
CVE-2025-64755
- EPSS 0.39%
- Veröffentlicht 21.11.2025 01:13:05
- Zuletzt bearbeitet 04.12.2025 18:03:51
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in ver...
CVE-2025-65099
- EPSS 0.44%
- Veröffentlicht 19.11.2025 17:35:17
- Zuletzt bearbeitet 25.11.2025 19:32:20
Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the startup trust d...
CVE-2025-59829
- EPSS 0.39%
- Veröffentlicht 03.10.2025 20:03:02
- Zuletzt bearbeitet 24.10.2025 19:45:17
Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, ...