8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.
Basic Information
ID
CVE-2025-54795
Source
GitHub_M
Published
Aug 5, 2025 at 00:07
Modified
Aug 5, 2025 at 14:21
Affected Product
Vendor
anthropics
Product
claude-code
Version
< 1.0.20
Affected Versions
anthropics claude-code < 1.0.20