PT-2025-31835 · Anthropic · Claude-Code

Elad Beber

·

Published

2025-08-02

·

Updated

2025-09-04

·

CVE-2025-54795

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 1.0.20
Description An error in command parsing allows bypassing the Claude Code confirmation prompt, potentially triggering the execution of untrusted commands. Successful exploitation requires the ability to inject untrusted content into a Claude Code context window.
Recommendations Update to version 1.0.20 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-13142
CVE-2025-54795
GHSA-X56V-X2H6-7J34

Affected Products

Claude-Code