216.73.217.22

CVE-2026-47092

· Published 18/05/2026 20:16 · Modified 18/05/2026 20:19

Labels: CVE-2026-47092 2026-05-18CVE-2026-47092CWE-427[email protected]

Essential information

Published
18/05/2026 20:16
Modified
18/05/2026 20:19
Author
Creator
CVSS
7.3 HIGH (v3) 7.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulting in arbitrary code execution on Windows systems.

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
claude-hud / claude hud cpe:2.3:a:claude-hud:claude_hud:0.0.12:*:*:*:*:*:*:*

References