OS Command Injection in Claude Code - CVE-2026-25723

 

OS Command Injection in Claude Code - CVE-2026-25723

Published: April 30, 2026


Vulnerability identifier: #VU128513
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25723
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands and write files outside intended restrictions.

The vulnerability exists due to command injection in the piped sed command handling in Claude Code when processing commands that use piped sed operations with the echo command. A remote attacker can send a specially crafted command to execute arbitrary commands and write files outside intended restrictions.

Exploitation requires the ability to execute commands through Claude Code with the "accept edits" feature enabled.


Affected software

Claude Code

How to mitigate CVE-2026-25723

Install security update from vendor's website.

Claude Code - update to 2.0.55

External References

Related Security Bulletins