PT-2026-6763 · Anthropic · Claude-Code
Nil221
·
Published
2026-02-06
·
Updated
2026-02-09
·
CVE-2026-25722
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Claude Code versions prior to 2.0.57
Description
Claude Code, an agentic coding tool, did not properly validate directory changes when combined with write operations to protected folders. Utilizing the
cd command to navigate into sensitive directories, such as .claude, allowed bypassing write protection, enabling the creation or modification of files without user confirmation. Successful exploitation required the ability to inject untrusted content into a Claude Code context window.Recommendations
Update to version 2.0.57 or later.
Exploit
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Claude-Code