216.73.216.197

CVE-2025-66032

· Published 03/12/2025 19:15 · Modified 05/12/2025 16:29

Labels: CVE-2025-66032 2025-12-03CVE-2025-66032CWE-77[email protected]

Essential information

Published
03/12/2025 19:15
Modified
05/12/2025 16:29
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
anthropic / claude code cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

References