Junglewise Threat Intelligence

CVE-2026-47092: jarrodwatts Claude HUD command injection via COMSPEC environment variable

CVE-2026-47092 · Severity: high · CVSS 7.8 · Published 2026-05-18

Technologies: Jarrodwatts Claude HUD. Vendors: Jarrodwatts.

Executive brief

Claude HUD, a terminal-based dashboard for Claude Code, is vulnerable to a security flaw on Windows systems that allows a local attacker to take control of the application. By manipulating a specific system setting (the COMSPEC environment variable) before the application starts, an attacker can trick the software into running a malicious program instead of the standard Windows command processor. This could lead to full system compromise or unauthorized data access on the user's computer.

Technical details

A command injection vulnerability exists in Claude HUD through version 0.0.12 within the version check component (`src/version.ts`). On Windows systems, the application retrieves the `COMSPEC` environment variable and passes it directly as the executable argument to `execFile()` without validation. A local attacker or a malicious process (such as a compromised npm script) can set `COMSPEC` to point to an arbitrary binary. When Claude HUD performs its periodic version check, it executes the attacker-controlled binary with `cmd.exe` arguments, leading to arbitrary code execution. This has been patched in commit 234d9aa by hardcoding the path to the system's legitimate `cmd.exe`.

Affected products

  • jarrodwatts Claude HUD through 0.0.12

Timeline

  • 2026-04-19: disclosed: Vulnerability reported to maintainer by Katriel Moses.
  • 2026-04-22: patched: Fix merged in commit 234d9aa.
  • 2026-05-18: advisory: CVE-2026-47092 published.

References

Related threats