Command Injection Vulnerability in Claude Code by Anthropic
CVE-2026-25723

7.7HIGH

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
6 February 2026

What is CVE-2026-25723?

Claude Code is an innovative coding tool that, prior to version 2.0.55, had a vulnerability allowing attackers to perform command injection through improper validation of piped sed operations with the echo command. This vulnerability could enable unauthorized writing to sensitive directories, including the .claude folder, and accessing paths beyond the intended project scope. The risk of exploitation required the 'accept edits' feature to be activated, creating an avenue for potential misuse. This issue has since been rectified in version 2.0.55.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

claude-code < 2.0.55

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.