CVE-2025-66032

Published Dec 3, 2025

Last updated 9 months ago

CVSS high 8.7
Claude Code

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-66032 describes a vulnerability found in Claude Code, an agentic coding tool, affecting versions prior to 1.0.93. The flaw arises from errors in how the tool parses shell commands, specifically those related to `$IFS` and short command-line interface (CLI) flags. This parsing vulnerability allows an attacker to bypass the read-only validation within Claude Code, potentially leading to arbitrary code execution. Successful exploitation of this issue requires the ability to introduce untrusted content into a Claude Code context window. The vulnerability has since been addressed and fixed in version 1.0.93 of Claude Code.

Description
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.
Source
security-advisories@github.com
NVD status
Analyzed
Products
claude_code

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-77

Social media

Hype score
Not currently trending
  1. In Dec 2025 a shell-parsing bug in Claude Code let untrusted text in the context window execute arbitrary code. CVE-2025-66032, CVSS 9.8. The security boundary was a parser deciding if a command was read-only. It lost to $IFS quoting. https://t.co/bC7VnbrM9h

    @Tosin_afolabi09

    5 Aug 2026

    1205 Impressions

    1 Retweet

    8 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  2. セキュリティリサーチャー RyotaK @ryotkak の技術ブログを公開しました。 今回、任意コマンドの実行に繋げられるClaude Codeの安全機構のバイパス手法を8つ発見し・報告しました。 脆弱性(CVE-2025-66032)が修正され

    @flatt_security

    12 Jan 2026

    13913 Impressions

    17 Retweets

    66 Likes

    36 Bookmarks

    0 Replies

    6 Quotes

  3. We've published a new blog post by RyotaK @ryotkak He discovered 8 methods to bypass safety mechanisms in Claude Code, leading to arbitrary command execution. We recommend updating to v1.0.93 or later to fix this vulnerability (CVE-2025-66032). https://t.co/sNu7Z9QoXk

    @flatt_sec_en

    12 Jan 2026

    40879 Impressions

    64 Retweets

    176 Likes

    140 Bookmarks

    1 Reply

    4 Quotes

  4. SECURITY ALERT: CVE-2025-66032 Exploit Fix & Mitigation Guide Read more: https://t.co/73jszGHeoN #Cybersecurity #CVE https://t.co/P9eSMMwGJP

    @SecReportCVE

    31 Dec 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-66032 Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Cla… https://t.co/OJimROA8fj

    @CVEnew

    3 Dec 2025

    197 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations