VDB
Sign up
HIGH

GHSA-xq4m-mc3c-vvg3

Claude Code Command Validation Bypass Allows Arbitrary Code Execution

Quick fix

GHSA-xq4m-mc3c-vvg3 — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.

npm install @anthropic-ai/claude-code@1.0.93

Details

Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Thank you to [RyotaK](hxxps://ryotak.net) from [GMO Flatt Security Inc.](hxxps://flatt.tech/en/) for reporting this issue!

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@anthropic-ai/claude-code
Introduced in: 0Fixed in: 1.0.93
Fixnpm install @anthropic-ai/claude-code@1.0.93

References