Executive brief
A vulnerability in the claude-code-cache-fix utility allows for local code execution when a user navigates into a specially crafted directory. This tool is used to manage status line information in Claude Code environments. An attacker could gain full access to the user's shell, files, and credentials by tricking them into downloading or accessing a folder with a malicious name.
Technical details
The vulnerability exists in `tools/quota-statusline.sh` due to the direct interpolation of user-controlled stdin payload into a Python triple-quoted string literal. An attacker can use a sequence of three single quotes (''') in a directory name or other workspace path to break out of the string literal and execute arbitrary Python code. This occurs automatically when the Claude Code statusline hook redraws, which happens upon entering a directory. The issue is fixed in version 3.5.2 by using environment variables and a single-quoted heredoc to safely pass data to Python.
Affected products
- cnighswonger claude-code-cache-fix >= 3.5.0, < 3.5.2
Timeline
- 2026-05-07: disclosed: Reported via GitHub issue #108
- 2026-05-07: patched: Version 3.5.2 published
- 2026-05-13: advisory: GitHub Advisory published