Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qgqw-h4xq-7w8w | Claude Code has a Command Injection in find Command Bypasses User Approval Prompt |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anthropics
Anthropics claude Code |
|
| Vendors & Products |
Anthropics
Anthropics claude Code |
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72. | |
| Title | Claude Code has a Command Injection in find Command Bypasses User Approval Prompt | |
| Weaknesses | CWE-78 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T21:19:42.986Z
Reserved: 2026-01-27T19:35:20.528Z
Link: CVE-2026-24887
Updated: 2026-02-03T21:19:37.560Z
Status : Awaiting Analysis
Published: 2026-02-03T21:16:13.433
Modified: 2026-02-04T16:33:44.537
Link: CVE-2026-24887
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:05:30Z
Github GHSA