Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
Modified: 12/22/2025
package
pkg:npm/%40anthropic-ai/claude-code
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
Modified: 12/22/2025
Claude Code can execute commands prior to the startup trust dialog
Modified: 10/3/2025
Claude Code has Permission Deny Bypass Through Symbolic Links
Modified: 4/12/2026
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
Modified: 7/9/2026
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Modified: 5/5/2026
Claude Code vulnerable to command execution prior to startup trust dialog
Modified: 12/22/2025
Claude Code permission deny bypass through symlink
Modified: 10/13/2025
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
Modified: 2/6/2026
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Modified: 7/24/2026
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Modified: 11/21/2025
Claude Code Improper Authorization via websocket connections from arbitrary origins
Modified: 6/27/2025
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
Modified: 2/6/2026
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Modified: 7/20/2026
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
Modified: 9/25/2025
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Modified: 2/3/2026
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
Modified: 2/6/2026
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Modified: 3/20/2026
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
Modified: 9/3/2025
Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
Modified: 8/5/2025
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
Modified: 5/8/2026
Claude Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes
Modified: 2/4/2026
Claude Code has a Command Injection in find Command Bypasses User Approval Prompt
Modified: 2/3/2026
Claude Code rg vulnerability does not protect against approval prompt bypass
Modified: 9/10/2025
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
Modified: 2/3/2026
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
Modified: 5/5/2026
Claude Code echo command allowed bypass of user approval prompt for command execution
Modified: 8/5/2025
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
Modified: 8/18/2025
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
Modified: 12/5/2025