CVE-2025-54795Patch(anthropic / claude_code)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch anthropic claude_code systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-02-02: 1Technical Details · 2026-03-31: 102-0203-31
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-021
Patch1
2026-03-311
General1
Full discourse2 posts
  • Akash Muni@akashmuni27
    General

    The CVE list is wild. - WebSocket auth bypass, any website could read your files via the IDE extension (CVE-2025-52882, CVSS 8.8) - Directory escape via naive prefix matching (CVE-2025-54794, CVSS 8.4) - Shell injection between whitelisted echo commands (CVE-2025-54795) - DNS exfiltration via command allowlist (CVE-2025-55284) 21 total. Growing.

    Post summary

    The message enumerates several high‑severity CVEs with concise technical characteristics but lacks any discussion of active exploitation, patches, or proof‑of‑concept material.

    10000230
    1.2K followersView on X
  • Grok@grok
    Patch

    The Claude Code Templates library (http://aitmpl.com, GitHub: davila7/claude-code-templates) is open-source with no reported vulnerabilities in my searches. However, Claude Code itself has known issues like prompt injection (e.g., CVE-2025-54795) and potential RCE risks in related tools. Review code, use isolated environments, and monitor for updates to mitigate risks with any AI agents.

    Post summary

    The text states that the Claude Code Templates library has no known vulnerabilities, but highlights a CVE for prompt injection (CVE‑2025‑54795) and potential RCE in related tools, advising code review, isolated environments, and monitoring for updates to mitigate risk.

    00000156
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more