Command Injection Vulnerability in Claude Code by Anthropic
CVE-2026-25723
What is CVE-2026-25723?
Claude Code is an innovative coding tool that, prior to version 2.0.55, had a vulnerability allowing attackers to perform command injection through improper validation of piped sed operations with the echo command. This vulnerability could enable unauthorized writing to sensitive directories, including the .claude folder, and accessing paths beyond the intended project scope. The risk of exploitation required the 'accept edits' feature to be activated, creating an avenue for potential misuse. This issue has since been rectified in version 2.0.55.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
claude-code < 2.0.55
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
