CVE-2025-66032

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 09:56

Type Values Removed Values Added
Summary
  • (es) Claude Code es una herramienta de codificación agéntica. Versiones anteriores a la 1.0.93, debido a errores en el análisis de comandos de shell relacionados con $IFS y flags CLI cortos, era posible eludir la validación de solo lectura de Claude Code y desencadenar la ejecución de código arbitrario. Explotar esto de forma fiable requiere la capacidad de añadir contenido no confiable en una ventana de contexto de Claude Code. Esta vulnerabilidad está corregida en la 1.0.93.

05 Dec 2025, 16:29

Type Values Removed Values Added
References () https://github.com/anthropics/claude-code/security/advisories/GHSA-xq4m-mc3c-vvg3 - () https://github.com/anthropics/claude-code/security/advisories/GHSA-xq4m-mc3c-vvg3 - Vendor Advisory
First Time Anthropic
Anthropic claude Code
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

03 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 19:15

Updated : 2026-06-17 09:56


NVD link : CVE-2025-66032

Mitre link : CVE-2025-66032

CVE.ORG link : CVE-2025-66032


JSON object : View

Products Affected

anthropic

  • claude_code
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')