CVE-2026-24887Patch(anthropic / claude_code)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch anthropic claude_code systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-03: 1Mentions · 2026-02-06: 2Mentions · 2026-05-05: 1Mentions · 2026-05-07: 1Mentions · 2026-05-11: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-06: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-11: 102-0302-0605-0505-0705-11
Signal classification4 categories
Patch
350.0%
Disclosure
116.7%
General
116.7%
Active Exploitation
116.7%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-062
General1Patch1
2026-05-051
Patch1
2026-05-071
Active Exploitation1
2026-05-111
Patch1
Full discourse6 posts
  • Giuliano F.@giulianofalco
    General

    Claude Code Update-Check: CVE-2026-24887 & 24053 sind keine Kleinigkeit. Wer agentische Tools nutzt, muss Hardening ernst nehmen. 🔒 🧵 Die Details warum das ZSH Clobber Parsing gefährlich war:

    Post summary

    The post highlights CVE-2026-24887 and CVE-2026-24053 as serious ZSH clobber parsing issues, urging hardening for users of agentic tools, but provides no technical, exploit, or patch details.

    1000047
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24887 Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to t… https://www.cve.org/CVERecord?id=CVE-2026-24887

    Post summary

    CVE‑2026‑24887 describes a command‑parsing flaw in Claude Code that permitted bypass of a confirmation prompt in versions before 2.0.72; the post provides technical detail but no PoC, exploit, or patch information.

    00010259
    56.5K followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-21852, CVE-2026-24887, CVE-2026-39861. Three Claude Code CVEs in one cycle: API-key exfil before the trust prompt, command injection via the find call, sandbox escape via symlink. Fixes shipped in 2.0.72 and 2.1.64. The SaaS Claude Code surface IS the threat surface. Self-hosted Claude Code with strict allowlists kills all three classes. https://aigeneral.net

    Post summary

    Three new Claude Code CVEs—API‑key exfiltration, command injection, and sandbox escape—have been disclosed with patches released and mitigations advised.

    0000073
    396 followersView on X
  • Martin Musiol@musiol_martin
    Active Exploitation

    CVE-2026-24887. CVE-2026-21852. CVE-2025-59536. Three Claude Code RCEs in 60 days, all weaponized faster after Anthropic shipped the full source map in a public npm bundle on March 31. The SaaS surface IS the threat surface. Self-hosted Claude Code behind strict allowlists kills the class. https://aigeneral.net

    Post summary

    Three remote code execution exploits in Claude Code were weaponized within 60 days after Anthropic published a public npm source map, exposing the SaaS surface as the main threat vector, with no patches or mitigations cited.

    000001.1K
    393 followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-24887: Claude Code <2.0.72 lets a malicious prompt bypass confirmation and run shell commands. Anthropic patched it. Every confirmation gate is one function call away from being skipped. Sandbox the agent, not the prompt. https://aigeneral.net

    Post summary

    Anthropic has patched CVE‑2026‑24887, a prompt‑bypass vulnerability in Claude that could allow shell command execution. The post highlights the patch and provides basic vulnerability details but no evidence of active exploitation.

    0000066
    392 followersView on X
  • Giuliano F.@giulianofalco
    Patch

    CVE-2026-24053: ZSH clobber (>|) Bypass → File Writes außerhalb des Workspaces möglich. CVE-2026-24887: Command Injection im 'find' Befehl → User-Approval Bypass. Fix: brew upgrade claude-code 🛡️ Stay safe.

    Post summary

    The tweet reports two vulnerabilities (ZSH clobber bypass and command injection in find) and offers a patch via "brew upgrade claude-code"; no PoC, exploit code, or active exploitation is mentioned.

    0000051
    58 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more