CVE-2025-55284
Last modified
CVE-2025-55284 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an overly broad allowlist of safe commands. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prompts to read a file and then send file contents over the network without user confirmation due to an overly broad allowlist of safe commands. Reliably exploiting this requires the ability to add untrusted content into a Claude Code context window. Users on standard Claude Code auto-update received this fix automatically after release. Current users of Claude Code are unaffected, as versions prior to 1.0.24 are deprecated and have been forced to update.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anthropic | Claude Code | < 1.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-55284?
How severe is CVE-2025-55284?
How do I fix CVE-2025-55284?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-55278Improper authentication in the API authentication middleware…8.1
- CVE-2025-55279This vulnerability exists in ZKTeco WL20 due to hard-coded p…6.9
- CVE-2025-5528The Social Sharing Plugin – Sassy Social Share plugin for Wo…6.1
- CVE-2025-55280This vulnerability exists in ZKTeco WL20 due to storage of W…5.2
- CVE-2025-55282aiven-db-migrate is an Aiven database migration tool. Prior …7.2
- CVE-2025-55283aiven-db-migrate is an Aiven database migration tool. Prior …7.2
- CVE-2025-55285@backstage/plugin-scaffolder-backend is the backend for the …2.6
- CVE-2025-55286z2d is a pure Zig 2D graphics library. z2d v0.7.0 released w…7.3
- CVE-2025-55287Genealogy is a family tree PHP application. Prior to 4.4.0, …5.4
- CVE-2025-55288Genealogy is a family tree PHP application. Prior to 4.4.0, …5.4
- CVE-2025-55289Chamilo is a learning management system. Prior to version 1.…9
- CVE-2025-5529The Educenter theme for WordPress is vulnerable to Stored Cr…6.4
Are you affected by CVE-2025-55284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
