Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
- No license file
- Private reporting disabled
- No update config
- 4/30 recent commits signed
- No code of conduct
- No contributing guide
- Needs admin access to check
- Needs admin access to check
- Needs security access to check
- SECURITY.md published
- Protected: no deletions, no force pushes, PRs required
- GitHub Actions configured
- Pushed today
- Issue templates configured
- moderate
Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
Jun 25, 2026
CVE-2026-46406 - high
Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Jun 25, 2026
CVE-2026-55607 - moderate
Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Jun 13, 2026
CVE-2026-54316 - high
SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
May 6, 2026
CVE-2026-44467 - high
Local Privilege Escalation via Directory Junction in CoworkVMService
May 6, 2026
CVE-2026-44470 - high
Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
Apr 24, 2026
CVE-2026-40068 - high
Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
Apr 20, 2026
CVE-2026-39861 - moderate
Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Apr 17, 2026
CVE-2026-35603 - high
Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Mar 18, 2026
CVE-2026-33068 - high
Command Injection via Directory Change Bypasses Write Protection
Feb 6, 2026
CVE-2026-25722 - high
Command Injection via Piped sed Command Bypasses File Write Restrictions
Feb 6, 2026
CVE-2026-25723 - high
Sandbox Escape via Persistent Configuration Injection in settings.json
Feb 6, 2026
CVE-2026-25725 - low
Permission Deny Bypass Through Symbolic Links
Feb 6, 2026
CVE-2026-25724 - high
Command Injection in find Command Bypasses User Approval Prompt
Feb 3, 2026
CVE-2026-24887 - high
Path Restriction Bypass via ZSH Clobber Allows Arbitrary File Writes
Feb 3, 2026
CVE-2026-24053 - high
Domain Validation Bypass Allows Automatic Requests to Attacker-Controlled Domains
Feb 3, 2026
CVE-2026-24052 - moderate
Malicious repo configuration can trigger data leakage via environment configuration used before trust confirmation
Jan 20, 2026
CVE-2026-21852 - high
Command Validation Bypass Allows Arbitrary Code Execution
Dec 3, 2025
CVE-2025-66032 - high
Sed Command Validation Bypass Allows Arbitrary File Writes
Nov 20, 2025
CVE-2025-64755 - high
Command execution prior to Claude Code startup trust dialog
Nov 19, 2025
CVE-2025-65099 - high
Command execution prior to Claude Code startup trust dialog
Oct 3, 2025
CVE-2025-59536 - low
Permission deny bypass through symlink
Oct 3, 2025
CVE-2025-59829 - high
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
Sep 24, 2025
CVE-2025-59828 - high
Command Injection in Claude Code rg command allowed bypass of user approval prompt for command execution
Sep 9, 2025
CVE-2025-58764 - high
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
Sep 9, 2025
CVE-2025-59041 - high
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
Sep 2, 2025
GHSA-ph6w-f82w-28w6 - high
Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
Aug 15, 2025
CVE-2025-55284 - high
Path Restriction Bypass in Claude Code Research Preview could allow unauthorized file access when path prefixes collide
Aug 1, 2025
CVE-2025-54794 - high
Command Injection in Claude Code echo command allowed bypass of user approval prompt for command execution
Aug 1, 2025
CVE-2025-54795 - high
Claude Code IDE extensions allow websocket connections from arbitrary origins
Jun 23, 2025
CVE-2025-52882