PT-2026-41731 · Unknown · Claude-Hud

·

CVE-2026-47091

·

Published

2026-05-18

·

Updated

2026-05-20

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Claude HUD versions 0.0.0 through 0.0.12
Description A path traversal issue allows attackers to read arbitrary files by providing an unvalidated transcript path value via stdin JSON. This enables access to any file readable by the process. Additionally, file metadata is written to a persistent cache file with insufficient permissions, which creates a forensic record of the accessed paths that remains after the process exits.
Recommendations Update to the version containing commit 234d9aa.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47091

Affected Products

Claude-Hud