VYPR

npm package

@anthropic-ai/claude-code

pkg:npm/%40anthropic-ai/claude-code

Vulnerabilities (24)

  • CVE-2025-55284Aug 16, 2025
    affected < 1.0.4fixed 1.0.4

    Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an overly broad allowlist of safe commands. Reliably exploiting

  • CVE-2025-54794Aug 5, 2025
    affected < 0.2.111fixed 0.2.111

    Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files outside the CWD. Successful exploitation depends on the presenc

  • CVE-2025-54795Aug 5, 2025
    affected < 1.0.20fixed 1.0.20

    Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a

  • CVE-2025-52882HigJun 24, 2025
    affected >= 0.2.116, < 1.0.24fixed 1.0.24

    Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-c

Page 2 of 2