Anthropic Claude Code vulnerabilities

23 known vulnerabilities affecting anthropic/claude_code.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH19MEDIUM1LOW2

Vulnerabilities

Page 2 of 2
CVE-2025-55284HIGHCVSS 7.1fixed in 1.0.42025-08-16
CVE-2025-55284 [HIGH] CWE-78 CVE-2025-55284: Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Co Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an overly broad allowlist of safe commands. Reliably exploiting this requires the ability to add untrusted content into a Claude Code con
nvd
CVE-2025-54794HIGHCVSS 7.7fixed in 0.2.1112025-08-05
CVE-2025-54794 [HIGH] CWE-22 CVE-2025-54794: Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefi Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files outside the CWD. Successful exploitation depends on the presence of (or ability to create) a directory with the same prefix as the CWD an
nvd
CVE-2025-54795HIGHCVSS 8.7fixed in 1.0.202025-08-05
CVE-2025-54795 [HIGH] CWE-78 CVE-2025-54795: Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes i Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.
nvd