Junglewise Threat Intelligence

CVE-2026-24053: Anthropic Claude Code path restriction bypass via ZSH clobber

CVE-2026-24053 · Severity: medium · CVSS 4 · Published 2026-02-03

Technologies: Anthropic Claude Code, @anthropic-ai/claude-code (npm). Vendors: Anthropic, npm.

Executive brief

Claude Code is an AI code execution environment used by developers to run code within Claude's AI interface. A vulnerability in Bash command parsing allows attackers who can inject untrusted code into a Claude Code session to write files outside the intended working directory, bypassing security restrictions—potentially compromising sensitive files on the developer's system without their knowledge or permission.

Technical details

The vulnerability is a path restriction bypass (CWE-22) and command injection issue (CWE-78) in Claude Code's Bash command validation logic. Due to improper parsing of ZSH clobber syntax (specifically `>|` operators), an attacker can escape directory restrictions that normally confine file writes to the current working directory. Exploitation requires the user to run ZSH as their shell and for the attacker to inject untrusted content into a Claude Code context window—a plausible scenario when processing user-provided code snippets or AI-generated code. An authenticated user, without triggering permission prompts, can write arbitrary files to any location accessible to the Claude Code process. The vulnerability has been patched in version 2.0.74; users on auto-update have received fixes, while others must manually update.

Affected products

  • Anthropic Claude Code < 2.0.74

Timeline

  • 2026-02-03: disclosed
  • 2026-02-03: patched: version 2.0.74

References

Related threats