Skip to content

claude-code

RCE vulnerability found in Claude Code

Claude News

Researchers discovered a remote code execution vulnerability in Claude Code version 2.1.118. The issue lies in the claude-cli deeplink handler and improper command-line argument parsing.

An attacker could craft a malicious link that, when clicked, launched Claude Code and silently loaded a malicious settings file. Due to a parsing error, config parameters were read directly from the request body. This led to arbitrary code execution on the victim's machine.

The threat was heightened by bypassing repository trust dialogs. If the link pointed to a trusted project, the utility ran stealthily. Developers patched the vulnerability in update 2.1.119. Users are advised to update the tool and inspect local config files for suspicious hooks.

Related stories

  1. Claude Code 2.1.282 ignores telemetry set by project files
  2. Two Claude Code sessions ate 32% of a team's bill
  3. One git call let a repo escape the Claude Code sandbox
  4. Claude Code opens network hosts one command at a time
  5. Stolen session keys are draining Claude Max accounts
  6. Claude Code under grith: 0.27% of calls reach a human

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.