Marci Ujlaki[verified]@UjlakiMarciDisclosure
CVE-2026-25725 is a critical privilege‑escalation flaw in Claude Code’s bubblewrap sandbox that exploits a missing settings file; patching to version 2.1.2 or later resolves the issue.
Prasenjit Sarkar[verified]@stretchcloudDisclosure
The tweet discloses CVE‑2026‑55607, explaining how worktree handling and symlink manipulation can lead to host code execution, and notes that a fix via auto‑update is recommended.
Ilan Kalendarov[verified]@IKalendarovPatch
A CVE‑2026‑25725 sandbox escape was found in Claude Code, Gemini CLI and Codex CLI; Anthropic released a fix, whereas Google and OpenAI either had no fix or treated it as informational.
Marci Ujlaki[verified]@UjlakiMarciGeneral
The post lists CVE-2026-25725 with its CWEs and links to EUVD and NVD but offers no PoC, exploit code, active exploitation, patch, or debunking information.
The Hacker Wire@TheHackerWireDisclosure
Claude Code's bubblewrap sandboxing flaw in versions before 2.1.2 can expose the .claude/settings.json file, as detailed in the linked vulnerability post.
CVE@CVEnewDisclosure
The tweet announces CVE‑2026‑25725, noting a sandboxing flaw in Claude Code prior to version 2.1.2, but provides no evidence of exploitation, patching, or a PoC. The information is a straightforward disclosure of a new vulnerability.
甲斐甲@k_aik_ouDisclosure
The tweet announces a newly discovered sandbox escape vulnerability in Claude Code (CVE‑2026‑25725) with a CVSS of 7.7, but does not provide any PoC, exploit, patch, or evidence of active exploitation.
CERT Azerbaijan@CERTAzerbaijanDisclosure
A new vulnerability, CVE-2026-25725, has been identified on the Claude Code platform, with a reference link provided for additional information.