CVE-2026-25722Disclosure(anthropic / claude_code)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate into sensitive directories like .claude, it was possible to bypass write protection and create or modify files without user confirmation. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.57.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-09: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-09: 102-0602-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25722 Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to prote… https://www.cve.org/CVERecord?id=CVE-2026-25722

    Post summary

    CVE-2026-25722 describes a directory validation flaw in Claude Code (v<2.0.57) that could be abused with certain write operations, but no PoC, exploit, or patch information is provided.

    80010186
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25722 - Critical Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By usin... https://www.thehackerwire.com/vulnerability/CVE-2026-25722/ https://t.co/yGeTiBHej5

    Post summary

    CVE-2026-25722 highlights a critical directory validation flaw in Claude Code prior to version 2.0.57, allowing writes to protected folders; no PoC, exploit, or active exploitation details are provided.

    70000157
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more