
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24053 is a path restriction bypass vulnerability in Anthropic's Claude Code (an agentic coding tool distributed as an npm package) that allows arbitrary file writes outside the current working directory. The flaw stems from a Bash command validation error in parsing ZSH clobber syntax, enabling attackers to bypass directory restrictions without triggering user permission prompts. It affects all versions of @anthropic-ai/claude-code prior to 2.0.74 and was disclosed on February 3, 2026. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.7 (High) (GitHub Advisory, Anthropic Advisory).
The root cause is improper input validation (CWE-20) combined with a path traversal weakness (CWE-22) and OS command injection elements (CWE-78) arising from how Claude Code's Bash command validator parses ZSH-specific clobber syntax (e.g., >| redirection operators). When a user runs Claude Code under ZSH, the tool's validation logic fails to correctly interpret clobber redirections, allowing crafted shell commands to write files to arbitrary filesystem locations outside the intended working directory. Exploitation requires two preconditions: the victim must be using ZSH as their shell, and an attacker must be able to inject untrusted content into the Claude Code context window (e.g., via prompt injection through malicious files, repositories, or web content processed by the agent) (GitHub Advisory, Anthropic Advisory).
Successful exploitation allows an attacker to write arbitrary files to any location accessible by the user running Claude Code, bypassing the tool's built-in directory restriction safeguards and without triggering permission prompts. This integrity impact could enable persistence mechanisms (e.g., writing to shell startup files, SSH authorized_keys, or cron directories), code injection into project files, or overwriting sensitive configuration files. While confidentiality and availability of subsequent systems are not directly impacted per the CVSS assessment, the ability to write files silently to arbitrary paths poses significant risk in developer environments where Claude Code typically operates with broad filesystem access (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.025% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement that the victim uses ZSH and that an attacker can influence the Claude Code context window, limiting the attack surface to prompt injection scenarios (GitHub Advisory).
@anthropic-ai/claude-code < 2.0.74) with ZSH as their default shell.echo 'malicious_content' >| /home/user/.zshrc or echo 'payload' >| ~/.ssh/authorized_keys.~/.zshrc, ~/.bashrc, ~/.ssh/authorized_keys, cron files, or other shell startup scripts) with timestamps correlating to Claude Code session activity.>|) targeting paths outside the project directory.Anthropic has patched this vulnerability in Claude Code version 2.0.74. Users on standard auto-update have already received the fix automatically. Users performing manual updates should upgrade to version 2.0.74 or later via npm update -g @anthropic-ai/claude-code. As a temporary workaround prior to patching, users can switch their default shell from ZSH to Bash when running Claude Code sessions, as the vulnerability is only exploitable under ZSH (GitHub Advisory, Anthropic Advisory).
The vulnerability was reported to Anthropic via HackerOne by researcher alexbernier and was acknowledged in the official advisory with a public credit (Anthropic Advisory). Red Hat also tracked the issue under their security advisory system (Red Hat CVE). No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."