SB2026043031 - OS Command Injection in Claude Code



SB2026043031 - OS Command Injection in Claude Code

Published: April 30, 2026

Security Bulletin ID SB2026043031
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) OS Command Injection (CVE-ID: CVE-2026-25722)

The vulnerability allows a remote attacker to create or modify files in protected directories without user confirmation.

The vulnerability exists due to improper input validation in directory change handling and write operations when processing untrusted content in a Claude Code context window. A remote attacker can use the cd command to navigate into sensitive directories such as .claude and perform write operations to create or modify files in protected directories without user confirmation.

Reliable exploitation requires the ability to add untrusted content into a Claude Code context window.


Remediation

Install update from vendor's website.