CVE-2025-66032

Published Dec 3, 2025

Last updated a month ago

CVSS high 8.7
Claude Code

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-66032 describes a vulnerability found in Claude Code, an agentic coding tool, affecting versions prior to 1.0.93. The flaw arises from errors in how the tool parses shell commands, specifically those related to `$IFS` and short command-line interface (CLI) flags. This parsing vulnerability allows an attacker to bypass the read-only validation within Claude Code, potentially leading to arbitrary code execution. Successful exploitation of this issue requires the ability to introduce untrusted content into a Claude Code context window. The vulnerability has since been addressed and fixed in version 1.0.93 of Claude Code.

Description
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.
Source
security-advisories@github.com
NVD status
Analyzed
Products
claude_code

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-77

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

35

Configurations