logo

Claude Code RCE Flaw Lets Attackers Execute Commands via Malicious Deeplinks

ID: 56311d44-b942-5371-8db6-68ba4d681d3f

STIX ID: report--56311d44-b942-5371-8db6-68ba4d681d3f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Guru Baran

...
...

A critical RCE in Anthropic's Claude Code CLI deeplink handler allowed attackers to embed a malicious --settings payload inside the deeplink q parameter due to eager, context-blind parsing of command-line arguments. By injecting a SessionStart hook, an attacker could execute arbitrary commands (e.g., bash -c 'id >/tmp/pwned.txt') when a user clicked the crafted link, and the flaw could bypass workspace trust if the deeplink referenced a trusted repo; Anthropic patched the issue in version 2.1.118 and users are urged to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.