VDB
Sign up
HIGH

GHSA-66q4-vfjg-2qhh

Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Quick fix

GHSA-66q4-vfjg-2qhh — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.

npm install @anthropic-ai/claude-code@2.0.57

Details

Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the `cd` command to navigate into sensitive directories like `.claude`, it was possible to bypass write protection and create or modify files without user confirmation. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window.

Users on standard Claude Code auto-update received this fix automatically. Users performing manual updates are advised to update to the latest version.

About Claude Code thanks hackerone.com/nil221 for reporting this issue!

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@anthropic-ai/claude-code
Introduced in: 0Fixed in: 2.0.57
Fixnpm install @anthropic-ai/claude-code@2.0.57

References