
In Dec 2025 a shell-parsing bug in Claude Code let untrusted text in the context window execute arbitrary code. CVE-2025-66032, CVSS 9.8. The security boundary was a parser deciding if a command was read-only. It lost to $IFS quoting. https://t.co/bC7VnbrM9h
Post summary
The tweet announces a high‑severity shell parsing vulnerability (CVE-2025‑66032) in Claude Code, describing the bug’s mechanics but providing no PoC, exploit code, patch, or evidence of active exploitation.

