CVE-2025-66032: Claude Code Command Validation Bypass Allows Arbitrary Code Execution
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.
Other sources
Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Thank you to RyotaK from GMO Flatt Security Inc. for reporting this issue!
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66032?
CVE-2025-66032 has a high severity due to its potential for arbitrary code execution.
How do I fix CVE-2025-66032?
To fix CVE-2025-66032, update to version 1.0.93 or later of the @anthropic-ai/claude-code package.
What causes CVE-2025-66032?
CVE-2025-66032 is caused by errors in parsing shell commands related to $IFS and short CLI flags.
Can CVE-2025-66032 be exploited remotely?
Yes, CVE-2025-66032 can be exploited if an attacker can add untrusted content into a Claude Code context window.
What software is affected by CVE-2025-66032?
CVE-2025-66032 affects the @anthropic-ai/claude-code package version prior to 1.0.93.