Name of the Vulnerable Software and Affected Versions:
Claude Code versions prior to 0.2.111
Claude Code versions prior to 1.0.24
Description:
Claude Code contains a path validation flaw where prefix matching is used instead of canonical path comparison. This allows bypassing directory restrictions and accessing files outside the current working directory (CWD). Successful exploitation requires the presence of, or the ability to create, a directory with the same prefix as the CWD and the ability to add untrusted content into a Claude Code context window.
Recommendations:
Update to version 0.2.111 or later.
Update to version 1.0.24 or later.