GHSA-xq4m-mc3c-vvg3
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
Quick fix
GHSA-xq4m-mc3c-vvg3 — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.
npm install @anthropic-ai/claude-code@1.0.93Details
Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Thank you to [RyotaK](hxxps://ryotak.net) from [GMO Flatt Security Inc.](hxxps://flatt.tech/en/) for reporting this issue!
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.93npm install @anthropic-ai/claude-code@1.0.93