PT-2026-41731 · Unknown · Claude-Hud

Katriel Moses

·

Published

2026-05-18

·

Updated

2026-05-20

·

CVE-2026-47091

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Claude HUD versions 0.0.0 through 0.0.12
Description A path traversal issue allows attackers to read arbitrary files by providing an unvalidated transcript path value via stdin JSON. This enables access to any file readable by the process. Additionally, file metadata is written to a persistent cache file with insufficient permissions, which creates a forensic record of the accessed paths that remains after the process exits.
Recommendations Update to the version containing commit 234d9aa.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-47091

Affected Products

Claude-Hud