Security: anthropics/claude-code
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Command Injection via Piped sed Command Bypasses File Write RestrictionsGHSA-mhg7-666j-cqg4 published
Feb 6, 2026 by ddworkenHigh -
Sandbox Escape via Persistent Configuration Injection in settings.jsonGHSA-ff64-7w26-62rf published
Feb 6, 2026 by ddworkenHigh -
Permission Deny Bypass Through Symbolic LinksGHSA-4q92-rfm6-2cqx published
Feb 6, 2026 by ddworkenLow -
Command Injection in find Command Bypasses User Approval PromptGHSA-qgqw-h4xq-7w8w published
Feb 3, 2026 by ddworkenHigh -
Path Restriction Bypass via ZSH Clobber Allows Arbitrary File WritesGHSA-q728-gf8j-w49r published
Feb 3, 2026 by ddworkenHigh -
Domain Validation Bypass Allows Automatic Requests to Attacker-Controlled DomainsGHSA-vhw5-3g5m-8ggf published
Feb 3, 2026 by ddworkenHigh -
Malicious repo configuration can trigger data leakage via environment configuration used before trust confirmationGHSA-jh7p-qr78-84p7 published
Jan 20, 2026 by ddworkenModerate -
Command Validation Bypass Allows Arbitrary Code ExecutionGHSA-xq4m-mc3c-vvg3 published
Dec 3, 2025 by ddworkenHigh -
Command execution prior to Claude Code startup trust dialogGHSA-5hhx-v7f6-x7gv published
Nov 19, 2025 by ddworkenHigh -
Sed Command Validation Bypass Allows Arbitrary File WritesGHSA-7mv8-j34q-vp7q published
Nov 20, 2025 by ddworkenHigh