Description
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.
References (4)
Core 4
Core References
Technical Description technical-description
https://github.com/jarrodwatts/claude-hud/issues/485
Issue Tracking issue-tracking
https://github.com/jarrodwatts/claude-hud/pull/487
Patch patch
https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf90b45ae35c23afc30
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/claude-hud-path-traversal-via-transcript-path
Scores
CVSS v3
3.3
EPSS
0.0013
EPSS Percentile
2.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (3)
jarrodwatts/claude-hud
< 0.0.12
jarrodwatts/claude-hud
234d9aad919b51326a43bcf90b45ae35c23afc30
jarrodwatts/claude_hud
< 0.0.12
Published
May 18, 2026
Tracked Since
May 19, 2026