Skip to content
AnthropicGHSA-xq4m-mc3c-vvg3

Command Validation Bypass Allows Arbitrary Code Execution

High8.7CVE-2025-66032 · Published Dec 3, 2025

Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to [RyotaK](hxxps://ryotak.net) from [GMO Flatt Security Inc.](hxxps://flatt.tech/en/) for reporting this issue!

GitHub advisory

Affected versions

PackageAffectedFixed in
@anthropic-ai/claude-code
npm
< v1.0.93v1.0.93
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-77

More Anthropic advisories

All Anthropic
Advisory
Anthropic: information disclosure
Medium5.3Jan 20
Network Sandboxing Escape
Low1.8Dec 4, 2025
Sed Command Validation Bypass Allows Arbitrary File Writes
High8.7Nov 20, 2025
Command execution prior to Claude Code startup trust dialog
High7.7Nov 19, 2025
Command execution prior to Claude Code startup trust dialog
High8.7Oct 3, 2025
Permission deny bypass through symlink
Low2.3Oct 3, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.