Vulnerability Details CVE-2025-54795
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-54795
-
cpe:2.3:a:anthropic:claude_code:0.2.100
-
cpe:2.3:a:anthropic:claude_code:0.2.101
-
cpe:2.3:a:anthropic:claude_code:0.2.102
-
cpe:2.3:a:anthropic:claude_code:0.2.103
-
cpe:2.3:a:anthropic:claude_code:0.2.104
-
cpe:2.3:a:anthropic:claude_code:0.2.105
-
cpe:2.3:a:anthropic:claude_code:0.2.106
-
cpe:2.3:a:anthropic:claude_code:0.2.107
-
cpe:2.3:a:anthropic:claude_code:0.2.108
-
cpe:2.3:a:anthropic:claude_code:0.2.113
-
cpe:2.3:a:anthropic:claude_code:0.2.114
-
cpe:2.3:a:anthropic:claude_code:0.2.115
-
cpe:2.3:a:anthropic:claude_code:0.2.116
-
cpe:2.3:a:anthropic:claude_code:0.2.117
-
cpe:2.3:a:anthropic:claude_code:0.2.118
-
cpe:2.3:a:anthropic:claude_code:0.2.120
-
cpe:2.3:a:anthropic:claude_code:0.2.122
-
cpe:2.3:a:anthropic:claude_code:0.2.123
-
cpe:2.3:a:anthropic:claude_code:0.2.124
-
cpe:2.3:a:anthropic:claude_code:0.2.125
-
cpe:2.3:a:anthropic:claude_code:0.2.126
-
cpe:2.3:a:anthropic:claude_code:0.2.14
-
cpe:2.3:a:anthropic:claude_code:0.2.18
-
cpe:2.3:a:anthropic:claude_code:0.2.19
-
cpe:2.3:a:anthropic:claude_code:0.2.25
-
cpe:2.3:a:anthropic:claude_code:0.2.27
-
cpe:2.3:a:anthropic:claude_code:0.2.29
-
cpe:2.3:a:anthropic:claude_code:0.2.30
-
cpe:2.3:a:anthropic:claude_code:0.2.31
-
cpe:2.3:a:anthropic:claude_code:0.2.32
-
cpe:2.3:a:anthropic:claude_code:0.2.33
-
cpe:2.3:a:anthropic:claude_code:0.2.34
-
cpe:2.3:a:anthropic:claude_code:0.2.35
-
cpe:2.3:a:anthropic:claude_code:0.2.36
-
cpe:2.3:a:anthropic:claude_code:0.2.37
-
cpe:2.3:a:anthropic:claude_code:0.2.38
-
cpe:2.3:a:anthropic:claude_code:0.2.39
-
cpe:2.3:a:anthropic:claude_code:0.2.40
-
cpe:2.3:a:anthropic:claude_code:0.2.41
-
cpe:2.3:a:anthropic:claude_code:0.2.42
-
cpe:2.3:a:anthropic:claude_code:0.2.43
-
cpe:2.3:a:anthropic:claude_code:0.2.44
-
cpe:2.3:a:anthropic:claude_code:0.2.45
-
cpe:2.3:a:anthropic:claude_code:0.2.46
-
cpe:2.3:a:anthropic:claude_code:0.2.47
-
cpe:2.3:a:anthropic:claude_code:0.2.48
-
cpe:2.3:a:anthropic:claude_code:0.2.49
-
cpe:2.3:a:anthropic:claude_code:0.2.50
-
cpe:2.3:a:anthropic:claude_code:0.2.51
-
cpe:2.3:a:anthropic:claude_code:0.2.52
-
cpe:2.3:a:anthropic:claude_code:0.2.53
-
cpe:2.3:a:anthropic:claude_code:0.2.54
-
cpe:2.3:a:anthropic:claude_code:0.2.55
-
cpe:2.3:a:anthropic:claude_code:0.2.56
-
cpe:2.3:a:anthropic:claude_code:0.2.57
-
cpe:2.3:a:anthropic:claude_code:0.2.59
-
cpe:2.3:a:anthropic:claude_code:0.2.60
-
cpe:2.3:a:anthropic:claude_code:0.2.61
-
cpe:2.3:a:anthropic:claude_code:0.2.62
-
cpe:2.3:a:anthropic:claude_code:0.2.64
-
cpe:2.3:a:anthropic:claude_code:0.2.65
-
cpe:2.3:a:anthropic:claude_code:0.2.66
-
cpe:2.3:a:anthropic:claude_code:0.2.67
-
cpe:2.3:a:anthropic:claude_code:0.2.68
-
cpe:2.3:a:anthropic:claude_code:0.2.69
-
cpe:2.3:a:anthropic:claude_code:0.2.70
-
cpe:2.3:a:anthropic:claude_code:0.2.72
-
cpe:2.3:a:anthropic:claude_code:0.2.73
-
cpe:2.3:a:anthropic:claude_code:0.2.74
-
cpe:2.3:a:anthropic:claude_code:0.2.76
-
cpe:2.3:a:anthropic:claude_code:0.2.77
-
cpe:2.3:a:anthropic:claude_code:0.2.78
-
cpe:2.3:a:anthropic:claude_code:0.2.79
-
cpe:2.3:a:anthropic:claude_code:0.2.80
-
cpe:2.3:a:anthropic:claude_code:0.2.81
-
cpe:2.3:a:anthropic:claude_code:0.2.83
-
cpe:2.3:a:anthropic:claude_code:0.2.84
-
cpe:2.3:a:anthropic:claude_code:0.2.85
-
cpe:2.3:a:anthropic:claude_code:0.2.86
-
cpe:2.3:a:anthropic:claude_code:0.2.89
-
cpe:2.3:a:anthropic:claude_code:0.2.9
-
cpe:2.3:a:anthropic:claude_code:0.2.90
-
cpe:2.3:a:anthropic:claude_code:0.2.91
-
cpe:2.3:a:anthropic:claude_code:0.2.92
-
cpe:2.3:a:anthropic:claude_code:0.2.93
-
cpe:2.3:a:anthropic:claude_code:0.2.94
-
cpe:2.3:a:anthropic:claude_code:0.2.96
-
cpe:2.3:a:anthropic:claude_code:0.2.97
-
cpe:2.3:a:anthropic:claude_code:0.2.98
-
cpe:2.3:a:anthropic:claude_code:0.2.99
-
cpe:2.3:a:anthropic:claude_code:1.0.0
-
cpe:2.3:a:anthropic:claude_code:1.0.1
-
cpe:2.3:a:anthropic:claude_code:1.0.10
-
cpe:2.3:a:anthropic:claude_code:1.0.11
-
cpe:2.3:a:anthropic:claude_code:1.0.14
-
cpe:2.3:a:anthropic:claude_code:1.0.15
-
cpe:2.3:a:anthropic:claude_code:1.0.16
-
cpe:2.3:a:anthropic:claude_code:1.0.17
-
cpe:2.3:a:anthropic:claude_code:1.0.18
-
cpe:2.3:a:anthropic:claude_code:1.0.19
-
cpe:2.3:a:anthropic:claude_code:1.0.2
-
cpe:2.3:a:anthropic:claude_code:1.0.3
-
cpe:2.3:a:anthropic:claude_code:1.0.4
-
cpe:2.3:a:anthropic:claude_code:1.0.5
-
cpe:2.3:a:anthropic:claude_code:1.0.6
-
cpe:2.3:a:anthropic:claude_code:1.0.7
-
cpe:2.3:a:anthropic:claude_code:1.0.8
-
cpe:2.3:a:anthropic:claude_code:1.0.9