GHSA-66q4-vfjg-2qhh
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
Quick fix
GHSA-66q4-vfjg-2qhh — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.
npm install @anthropic-ai/claude-code@2.0.57Details
Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the `cd` command to navigate into sensitive directories like `.claude`, it was possible to bypass write protection and create or modify files without user confirmation. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window.
Users on standard Claude Code auto-update received this fix automatically. Users performing manual updates are advised to update to the latest version.
About Claude Code thanks hackerone.com/nil221 for reporting this issue!
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.0.57npm install @anthropic-ai/claude-code@2.0.57