{"id":"CVE-2025-55284","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-55284","summary":"Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code","details":"Due to an overly broad allowlist of safe commands, it was possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. \n\nUsers on standard Claude Code auto-update received this fix automatically after release. Current users of Claude Code are unaffected, as versions prior to 1.0.24 are deprecated and have been forced to update.\n\nThank you to https://hackerone.com/wunderwuzzi23 for reporting this issue!","published":"2025-08-18T18:46:52Z","modified":"2025-08-18T20:27:29.564350Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/claude-code","fixedVersion":"1.0.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-x5gv-jw7f-j6xj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55284"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-18T20:27:29.564350Z"}}