CVE-2026-24053: 
Claude Code vulnerability analysis and mitigation

Overview

CVE-2026-24053 is a path restriction bypass vulnerability in Anthropic's Claude Code (an agentic coding tool distributed as an npm package) that allows arbitrary file writes outside the current working directory. The flaw stems from a Bash command validation error in parsing ZSH clobber syntax, enabling attackers to bypass directory restrictions without triggering user permission prompts. It affects all versions of @anthropic-ai/claude-code prior to 2.0.74 and was disclosed on February 3, 2026. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.7 (High) (GitHub Advisory, Anthropic Advisory).

Technical details

The root cause is improper input validation (CWE-20) combined with a path traversal weakness (CWE-22) and OS command injection elements (CWE-78) arising from how Claude Code's Bash command validator parses ZSH-specific clobber syntax (e.g., >| redirection operators). When a user runs Claude Code under ZSH, the tool's validation logic fails to correctly interpret clobber redirections, allowing crafted shell commands to write files to arbitrary filesystem locations outside the intended working directory. Exploitation requires two preconditions: the victim must be using ZSH as their shell, and an attacker must be able to inject untrusted content into the Claude Code context window (e.g., via prompt injection through malicious files, repositories, or web content processed by the agent) (GitHub Advisory, Anthropic Advisory).

Impact

Successful exploitation allows an attacker to write arbitrary files to any location accessible by the user running Claude Code, bypassing the tool's built-in directory restriction safeguards and without triggering permission prompts. This integrity impact could enable persistence mechanisms (e.g., writing to shell startup files, SSH authorized_keys, or cron directories), code injection into project files, or overwriting sensitive configuration files. While confidentiality and availability of subsequent systems are not directly impacted per the CVSS assessment, the ability to write files silently to arbitrary paths poses significant risk in developer environments where Claude Code typically operates with broad filesystem access (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.025% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement that the victim uses ZSH and that an attacker can influence the Claude Code context window, limiting the attack surface to prompt injection scenarios (GitHub Advisory).

Exploitation steps

  1. Identify target: Confirm the target user is running Claude Code (@anthropic-ai/claude-code < 2.0.74) with ZSH as their default shell.
  2. Craft malicious content: Prepare untrusted content (e.g., a malicious file, README, or web page) containing a ZSH clobber syntax payload designed to redirect output to a path outside the working directory, such as: echo 'malicious_content' >| /home/user/.zshrc or echo 'payload' >| ~/.ssh/authorized_keys.
  3. Inject into context window: Deliver the malicious content into the Claude Code context window via prompt injection — for example, by having the agent read a malicious file in a repository, process a crafted document, or browse a malicious web page.
  4. Trigger command execution: Claude Code, while processing the injected content, generates and executes a shell command using ZSH clobber syntax; the flawed Bash validator fails to flag the out-of-directory write.
  5. Achieve arbitrary file write: The file is written to the attacker-specified path without user permission prompts, enabling persistence, privilege escalation setup, or code injection depending on the target path (GitHub Advisory, Anthropic Advisory).

Indicators of compromise

  • File System: Unexpected new or modified files outside the Claude Code working directory (e.g., changes to ~/.zshrc, ~/.bashrc, ~/.ssh/authorized_keys, cron files, or other shell startup scripts) with timestamps correlating to Claude Code session activity.
  • Logs: Shell history or Claude Code session logs showing ZSH clobber redirection operators (>|) targeting paths outside the project directory.
  • Process: Claude Code process spawning shell commands that write to paths outside the expected working directory; unexpected file modification events on sensitive user configuration files during or shortly after a Claude Code session.
  • Network: Outbound connections from the host following unexpected file modifications, which may indicate a follow-on payload was written and executed (e.g., a backdoor or reverse shell script added to a startup file).

Mitigation and workarounds

Anthropic has patched this vulnerability in Claude Code version 2.0.74. Users on standard auto-update have already received the fix automatically. Users performing manual updates should upgrade to version 2.0.74 or later via npm update -g @anthropic-ai/claude-code. As a temporary workaround prior to patching, users can switch their default shell from ZSH to Bash when running Claude Code sessions, as the vulnerability is only exploitable under ZSH (GitHub Advisory, Anthropic Advisory).

Community reactions

The vulnerability was reported to Anthropic via HackerOne by researcher alexbernier and was acknowledged in the official advisory with a public credit (Anthropic Advisory). Red Hat also tracked the issue under their security advisory system (Red Hat CVE). No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related Claude Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55607HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026
CVE-2026-40068HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesMay 05, 2026
CVE-2026-39861HIGH7.7
  • Claude Code logoClaude Code
  • @anthropic-ai/claude-code
NoYesApr 21, 2026
CVE-2026-54316MEDIUM6
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 23, 2026
CVE-2026-46406MEDIUM4.4
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management