PT-2025-26782 · Unknown+6 · Claude Code [Beta]+9
Published
2025-06-23
·
Updated
2026-03-31
·
CVE-2025-52882
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions:
Claude Code for VSCode IDE extensions versions 0.2.116 through 1.0.23
Claude Code [beta] for JetBrains IDE plugins versions 0.1.1 through 0.1.8
Description:
The issue allows unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. This could enable an attacker to read arbitrary files, see the list of files open in the IDE, get selection and diagnostics events from the IDE, or execute code in limited situations where a user has an open Jupyter Notebook and accepts a malicious prompt in VSCode and its forks. In JetBrains IDEs, an attacker could get selection events, a list of open files, and a list of syntax errors.
Recommendations:
For VSCode, Cursor, Windsurf, VSCodium, and other VSCode forks, check the extension Claude Code for VSCode, update or uninstall any version prior to 1.0.24, and restart the IDE.
For JetBrains IDEs including IntelliJ, PyCharm, and Android Studio, check the plugin Claude Code [Beta], update or uninstall any version prior to 0.1.9, and restart the IDE.
Exploit
Fix
RCE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android Studio
Claude Code [Beta]
Claude Code For Vscode
Cursor
Intellij
Jetbrains Rider
Pycharm
Vscode
Vscodium
Windsurf