CVE-2026-31975
- EPSS 0.61%
- Veröffentlicht 11.03.2026 17:27:06
- Zuletzt bearbeitet 20.03.2026 16:17:49
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from th...
CVE-2026-31861
- EPSS 0.06%
- Veröffentlicht 11.03.2026 17:22:10
- Zuletzt bearbeitet 17.03.2026 19:06:41
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell commands by interpolating user-supplied gitName and gitEmail values into...
CVE-2026-31862
- EPSS 0.07%
- Veröffentlicht 11.03.2026 17:17:47
- Zuletzt bearbeitet 17.03.2026 19:04:29
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpolation of user-controlled parameters (file, branch, m...