Executive brief
Claude Code is an AI-powered code execution environment used to help developers write and test code. A validation bypass in command parsing allows attackers who can inject untrusted content into Claude Code sessions to execute arbitrary system commands, potentially compromising the developer's system and accessing sensitive data or credentials.
Technical details
The vulnerability stems from errors in parsing shell commands, specifically related to improper handling of $IFS (Internal Field Separator) and short CLI flags. The Claude Code read-only validation mechanism can be bypassed through crafted shell command input, allowing arbitrary code execution. Exploitation requires the ability to add untrusted content into a Claude Code context window (e.g., via prompts containing malicious payloads). An attacker can achieve full code execution with the privileges of the user running Claude Code. The vulnerability has been patched in version 1.0.93 and later; users with auto-update enabled have already received the fix.
Affected products
- Anthropic Claude Code <1.0.93
Timeline
- 2025-12-03: disclosed: Vulnerability disclosed via GitHub advisory
- 2025-12-03: patched: Patched in version 1.0.93