CVE-2026-31975Disclosure(cloudcli / cloud_cli)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from the WebSocket message payload and interpolated into a bash command string without any sanitization, enabling arbitrary OS command execution. A secondary injection vector exists via unsanitized sessionId. This vulnerability is fixed in 1.25.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_cli

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
cloud_cli

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Technical Details · 2026-03-12: 203-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31975 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shel… https://www.cve.org/CVERecord?id=CVE-2026-31975 ----- Traducción: CVE-2026-31975 Clo… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑31975, describing an OS command injection vulnerability in Cloud CLI via WebSocket, but does not provide PoC, exploit code, active exploitation data, or patches.

    0000093
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31975 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shel… https://www.cve.org/CVERecord?id=CVE-2026-31975

    Post summary

    The snippet announces CVE-2026-31975, noting an OS Command Injection via WebSocket in Cloud CLI prior to version 1.25.0, without mentioning exploitation, PoC, or patch.

    00000282
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudclicloud_cli---

Explore more