Critical severity9.8NVD Advisory· Published Aug 5, 2025· Updated Jun 17, 2026
CVE-2025-54795
CVE-2025-54795
Description
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. This is fixed in version 1.0.20.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@anthropic-ai/claude-codenpm | < 1.0.20 | 1.0.20 |
Affected products
3< 1.0.20+ 1 more
- (no CPE)range: < 1.0.20
- cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*range: <1.0.20
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-x56v-x2h6-7j34ghsaADVISORY
- github.com/anthropics/claude-code/security/advisories/GHSA-x56v-x2h6-7j34nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-54795ghsaADVISORY
News mentions
0No linked articles in our index yet.