Ad

CVE-2026-24887

HIGH CVSS 4.0: 7.7 EPSS 0.04%
Updated Feb 04, 2026
Claude
Parameter Value
CVSS 7.7 (HIGH)
Fixed In 2.0.72
Type CWE-94 (Code Injection (Внедрение кода)), CWE-78 (OS Command Injection (Внедрение команд ОС))
Vendor Claude
Public PoC No

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window.

This issue has been patched in version 2.0.72.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
Present
Нужны дополнительные условия
Privileges Required
None
Права не нужны
User Interaction
Passive
Минимальное взаимодействие

Impact Assessment

Confidentiality
High
Полная утечка данных
Integrity
High
Полная модификация данных
Availability
High
Полный отказ в обслуживании

CVSS Vector v4.0