CVE-2025-66032
EPSS 0.04%Claude Code Command Validation Bypass Allows Arbitrary Code Execution
Published: 12/3/2025Modified: 12/5/2025
Also known as:GHSA-xq4m-mc3c-vvg3
Description
Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to [RyotaK](hxxps://ryotak.net) from [GMO Flatt Security Inc.](hxxps://flatt.tech/en/) for reporting this issue!
Affected packages (1)
- npm/@anthropic-ai/claude-codefrom 0, < 1.0.93
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |