CVE-2026-25723

MEDIUM

Anthropic Claude Code < 2.0.55 - OS Command Injection

Title source: rule
STIX 2.1

Description

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the echo command, allowing attackers to bypass file write restrictions. This vulnerability enabled writing to sensitive directories like the .claude folder and paths outside the project scope. Exploiting this required the ability to execute commands through Claude Code with the "accept edits" feature enabled. This issue has been patched in version 2.0.55.

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-20
Status published
Products (2)
anthropic/claude_code < 2.0.55
anthropic-ai/claude-code 0 - 2.0.55npm
Published Feb 06, 2026
Tracked Since Feb 18, 2026