Preliminary research
Pwning Claude Code in 8 Different Ways
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Claude Code allowlists read-only commands such as echo, sort and sed, then guards them with a blocklist over their arguments. Eight bypasses of that blocklist reach command execution with no approval prompt: unfiltered arguments, git's ambiguous argument parsing, sed's e command, two tools reading one argument differently, and a bash variable-expansion chain. CVE-2025-66032, fixed in v1.0.93.
Record
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .