CVE-2026-31862Disclosure(cloudcli / cloud_cli)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cloudcli cloud_cli systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpolation of user-controlled parameters (file, branch, message, commit), allowing authenticated attackers to execute arbitrary OS commands. This vulnerability is fixed in 1.24.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_cli

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-11); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
cloud_cli

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 2Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 103-1103-1203-1703-18
Signal classification3 categories
Disclosure
342.9%
Patch
342.9%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2Patch1
2026-03-122
Disclosure1General1
2026-03-171
Patch1
2026-03-181
Patch1
Full discourse7 posts
  • Wazuh@wazuh
    Patch

    Cloud CLI (Claude Code UI) is affected by CVE-2026-31862 (CVSS 9.1), a critical command injection flaw in Git API endpoints that may allow authenticated attackers to execute OS commands. Update to 1.24.0 or later now. Read more: https://ow.ly/r77g50YvcVu https://t.co/DV04tomxo8

    Post summary

    The post warns that Cloud CLI is vulnerable to CVE‑2026‑31862, a critical command injection flaw, and urges users to upgrade to version 1.24.0 or newer.

    11904374.9K
    7.9K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @wazuh Cloud CLI command injection is dev nightmare fuel! CVE-2026-31862 with CVSS 9.1 in Claude Code UI Git APIs = authenticated RCE in development environments. Developer tooling security strikes again - update to 1.24.0 ASAP! https://vulntracker.io/cves/CVE-2026-31862

    Post summary

    CVE‑2026‑31862 is a high‑severity authenticated RCE via command injection in the Claude Code UI Git APIs, with a CVSS score of 9.1, and users are advised to update to version 1.24.0 immediately.

    00000133
    433 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-31862 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use … https://www.cve.org/CVERecord?id=CVE-2026-31862 ----- Traducción: CVE-2026-31862 Clo… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑31862 but offers minimal technical detail, no PoC, exploit, or patch information.

    00000110
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31862 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use … https://www.cve.org/CVERecord?id=CVE-2026-31862

    Post summary

    The text briefly announces that CVE‑2026‑31862 impacts Cloud CLI before version 1.24.0 due to unspecified Git‑related API issues, with no PoC, exploit, patch, or active exploitation details provided.

    00000267
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31862: CRITICAL] Cloud CLI patched a critical OS command injection vulnerability in version 1.24.0, preventing attackers from exploiting Git-related API endpoints. Update now for enhanced security.#cve,CVE-2026-31862,#cybersecurity https://cvefind.com/CVE-2026-31862

    Post summary

    Cloud CLI version 1.24.0 has been patched for a critical OS command injection vulnerability (CVE‑2026‑31862); users are advised to update immediately.

    0000042
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31862 - Critical Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with stri... https://www.thehackerwire.com/vulnerability/CVE-2026-31862/ https://t.co/NHkJC4XCOR

    Post summary

    The post announces a critical CVE-2026-31862 affecting Cloud CLI before version 1.24.0, providing limited technical detail about execAsync usage, with no PoC, exploit, patch, or active exploitation information disclosed.

    0000098
    134 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31862: Cloud CLI has Command Injection ... String interpolation in execAsync() across Git endpoints = trivial RCE for any authenticated user - classic footgun pat... https://zerodaysignal.com/vulnerability/CVE-2026-31862 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts on CVE-2026-31862, a trivial RCE in Cloud CLI caused by string interpolation in execAsync()—any authenticated user can exploit it, with more details referenced via the provided link.

    0000056
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudclicloud_cli---

Explore more