CVE-2026-24053
CVE-2026-24053 is a medium-severity vulnerability in Anthropic Claude Code with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.7
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-5156
- Weakness: CWE-22
- Affected product: Anthropic Claude Code
- Published:
- Last modified:
Description
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploiting this required the user to use ZSH and the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.74.
Frequently asked questions
- What is CVE-2026-24053?
- Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploiting this required the user to use ZSH and the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.74.
- How severe is CVE-2026-24053?
- CVE-2026-24053 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-24053 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-24053?
- CVE-2026-24053 affects Anthropic Claude Code. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-24053?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-24053 have an EU (EUVD) identifier?
- Yes. CVE-2026-24053 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-5156.
- When was CVE-2026-24053 published?
- CVE-2026-24053 was published on 2026-02-03 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*
More vulnerabilities in Anthropic Claude Code
- CVE-2026-39861 — Critical (CVSS 10.0): Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed…
- CVE-2026-25725 — Critical (CVSS 10.0): Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to…
- CVE-2025-66032 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and…
- CVE-2025-64755 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible…
- CVE-2025-65099 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above,…
- CVE-2025-59828 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions…
All CVEs affecting Anthropic Claude Code →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.