PT-2026-41731 · Unknown · Claude-Hud
Katriel Moses
·
Published
2026-05-18
·
Updated
2026-05-20
·
CVE-2026-47091
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Claude HUD versions 0.0.0 through 0.0.12
Description
A path traversal issue allows attackers to read arbitrary files by providing an unvalidated
transcript path value via stdin JSON. This enables access to any file readable by the process. Additionally, file metadata is written to a persistent cache file with insufficient permissions, which creates a forensic record of the accessed paths that remains after the process exits.Recommendations
Update to the version containing commit 234d9aa.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Claude-Hud