Executive brief
Claude Code is an AI-powered code execution tool that normally requires user confirmation before reading files or sending data over the network. A flaw in the default command allowlist made it possible to bypass these safety prompts by chaining permitted commands, allowing attackers to read sensitive files and transmit their contents without user knowledge. This requires the attacker to inject malicious code into a Claude Code session, typically through untrusted content in a chat context.
Technical details
Claude Code implements a confirmation prompt system to gate sensitive operations like file reads and network requests. Due to an overly broad allowlist of commands considered "safe," an attacker could chain multiple permitted commands to circumvent these protections and read arbitrary files, then exfiltrate their contents over the network without triggering user confirmation. The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). Exploitation requires the ability to inject untrusted content into a Claude Code context window (e.g., via a malicious code snippet in a chat). Patches were released in version 1.0.4, with automatic updates deployed to standard users; legacy versions prior to 1.0.24 have been deprecated and forced to update.
Affected products
- Anthropic Claude Code < 1.0.4
Timeline
- 2025-08-15: disclosed
- 2025-08-18: patched: Version 1.0.4 released with fix