CVE-2025-66032 - CVE House
Back to Database
Status published High CVE-2025-66032

Claude Code Command Validation Bypass Allows Arbitrary Code Execution

Vulnerability Description

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 1.0.93.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66032

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

claude-code
Vulnerable Versions:
< 1.0.93

Timeline

Official Publish: December 3rd, 2025
Last Modified: December 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)