Anthropics Claude-Code vulnerabilities
23 known vulnerabilities affecting anthropics/claude-code.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH19MEDIUM2LOW2
Vulnerabilities
Page 2 of 2
CVE-2025-54794HIGHCVSS 7.7fixed in 0.2.1112025-08-05
CVE-2025-54794 [HIGH] CWE-22 CVE-2025-54794: Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefi
Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files outside the CWD. Successful exploitation depends on the presence of (or ability to create) a directory with the same prefix as the CWD an
nvd
CVE-2025-54795HIGHCVSS 8.7fixed in 1.0.202025-08-05
CVE-2025-54795 [HIGH] CWE-78 CVE-2025-54795: Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes i
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.
nvd
CVE-2025-52882HIGHCVSS 8.8v>= 0.2.116 < 1.0.242025-06-24
CVE-2025-52882 [HIGH] CWE-1385 CVE-2025-52882: Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Win
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for VSCode IDE extensions versions 0.2.1
nvd
← Previous2 / 2