CVE-2026-31862 is a high-severity OS command injection vulnerability affecting Cloud CLI (aka Claude Code UI) versions prior to 1.24.0. Rated 8.8 CVSS, this flaw allows authenticated attackers to remotely execute arbitrary operating system commands with low privileges and no user interaction, leading to high impact on confidentiality, integrity, and availability. While not actively exploited or having public exploit code, it is designated as "Hot List: Active" and has garnered community discussion, indicating significant attention. Organizations using affected versions should upgrade to 1.24.0 to remediate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.24.0CPE matchmatch criteria | cpe:2.3:a:cloudcli:cloud_cli:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.