{"id":"CVE-2026-25722","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-25722","summary":"Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection","details":"Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the `cd` command to navigate into sensitive directories like `.claude`, it was possible to bypass write protection and create or modify files without user confirmation. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. \n\nUsers on standard Claude Code auto-update received this fix automatically. Users performing manual updates are advised to update to the latest version.\n\nAbout\nClaude Code thanks hackerone.com/nil221 for reporting this issue!","published":"2026-02-06T19:02:41Z","modified":"2026-02-06T19:56:44.198671Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/claude-code","fixedVersion":"2.0.57"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-66q4-vfjg-2qhh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25722"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-06T19:56:44.198671Z"}}