PT-2026-6214 · Anthropic · Claude-Code

·

CVE-2026-24887

·

Published

2026-02-03

·

Updated

2026-05-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 2.0.72
Description Claude Code is an agentic coding tool. A flaw in command parsing allowed bypassing the confirmation prompt, potentially triggering the execution of untrusted commands via the find command. Successful exploitation required the ability to inject untrusted content into a Claude Code context window. The issue was addressed in version 2.0.72.
Recommendations Update to version 2.0.72 or later.

Exploit

Fix

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24887
GHSA-QGQW-H4XQ-7W8W

Affected Products

Claude-Code