Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242427
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109057
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148636
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7835-87q9-rgvv
npm/@anthropic-ai/claude-code
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
24 Jul
Fix available
Severity - 7.7 (High)
GHSA-4vp2-6q8c-pvq2
npm/@anthropic-ai/claude-code
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
25 Jun
Fix available
Severity - 4.4 (Medium)
GHSA-fg94-h982-f3mm
npm/@anthropic-ai/claude-code
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
17 Jun
Fix available
Severity - 6.0 (Medium)
GHSA-q5hj-mxqh-vv77
npm/@anthropic-ai/claude-code
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
24 Apr
Fix available
Severity - 7.7 (High)
GHSA-vp62-r36r-9xqp
npm/@anthropic-ai/claude-code
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
21 Apr
Fix available
Severity - 7.7 (High)
GHSA-5cwg-9f6j-9jvx
npm/@anthropic-ai/claude-code
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
17 Apr
Fix available
Severity - 5.4 (Medium)
GHSA-mmgp-wc2j-qcv7
npm/@anthropic-ai/claude-code
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
19 Mar
Fix available
Severity - 7.7 (High)
GHSA-ff64-7w26-62rf
npm/@anthropic-ai/claude-code
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
06 Feb
Fix available
Severity - 7.7 (High)
GHSA-4q92-rfm6-2cqx
npm/@anthropic-ai/claude-code
Claude Code has Permission Deny Bypass Through Symbolic Links
06 Feb
Fix available
Severity - 2.3 (Low)
GHSA-mhg7-666j-cqg4
npm/@anthropic-ai/claude-code
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
06 Feb
Fix available
Severity - 7.7 (High)
GHSA-66q4-vfjg-2qhh
npm/@anthropic-ai/claude-code
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
06 Feb
Fix available
Severity - 7.7 (High)
GHSA-qgqw-h4xq-7w8w
npm/@anthropic-ai/claude-code
Claude Code has a Command Injection in find Command Bypasses User Approval Prompt
03 Feb
Fix available
Severity - 7.7 (High)
GHSA-q728-gf8j-w49r
npm/@anthropic-ai/claude-code
Claude Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes
03 Feb
Fix available
Severity - 7.7 (High)
GHSA-vhw5-3g5m-8ggf
npm/@anthropic-ai/claude-code
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
03 Feb
Fix available
Severity - 7.1 (High)
GHSA-jh7p-qr78-84p7
npm/@anthropic-ai/claude-code
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
21 Jan
Fix available
Severity - 5.3 (Medium)
GHSA-xq4m-mc3c-vvg3
npm/@anthropic-ai/claude-code
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
03 Dec 2025
Fix available
Severity - 8.7 (High)
Load more...
npm - OSV