Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropic
Anthropic claude Code |
|
| CPEs | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Anthropic
Anthropic claude Code |
|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropics
Anthropics claude Code |
|
| Vendors & Products |
Anthropics
Anthropics claude Code |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72. | |
| Title | Claude Code has a Command Injection in find Command Bypasses User Approval Prompt | |
| Weaknesses | CWE-78 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-03T20:50:25.263Z
Updated: 2026-02-03T21:19:42.986Z
Reserved: 2026-01-27T19:35:20.528Z
Link: CVE-2026-24887
Updated: 2026-02-03T21:19:37.560Z
Status : Analyzed
Published: 2026-02-03T21:16:13.433
Modified: 2026-02-06T20:19:47.760
Link: CVE-2026-24887
No data.