Command Execution Vulnerability in Claude Code by Anthropic
CVE-2025-54795
8.7HIGH
What is CVE-2025-54795?
In versions prior to 1.0.20, Claude Code, an agentic coding tool developed by Anthropic, suffers from a command execution flaw due to improper command parsing. This vulnerability allows attackers to bypass the confirmation prompt, enabling them to execute untrusted commands. To exploit this vulnerability, an attacker must have the capability to introduce malicious content into the Claude Code context window. This issue was addressed in version 1.0.20, highlighting the importance of keeping software up-to-date for maintaining security.
Affected Version(s)
claude-code < 1.0.20
