logo

CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions

ID: dd0c783e-424c-5035-b855-188483d2e686

STIX ID: report--dd0c783e-424c-5035-b855-188483d2e686

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-08-26

Date Updated: 2026-04-27

...
...

A critical unauthenticated WebSocket vulnerability (CVE-2025-52882, CVSS 8.8) in Anthropic's Claude Code IDE extensions for VS Code allowed malicious websites to connect to local MCP servers on localhost, enabling attackers to execute MCP commands, read local files, and run code in notebooks; the issue has been fixed in version 1.0.24 and earlier vulnerable versions removed from extension marketplaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.