CVE-2026-35570 is a logic flaw in OpenClaude versions prior to 0.5.1, an open-source coding-agent command line interface for cloud and local model providers. The vulnerability exists in the bashToolHasPermission() function within the bash permissions module, where the sandbox auto-allow feature bypasses critical path constraint validation, allowing attackers to use path traversal sequences to access restricted files and directories. The vulnerability carries a CVSS 3.1 score of 8.4 (HIGH) and requires local access with low privileges to exploit. The attack is deterministic with no user interaction required, and successful exploitation could result in high confidentiality and integrity impacts across multiple components of the system. The FAUCET risk score of 50.0 reflects moderate overall risk when considering environmental factors. There is currently no evidence of active exploitation in the wild, as indicated by the inactive status on the CISA KEV catalog. The EPSS score of 0.00006 suggests exploitation likelihood is very low relative to the broader CVE population. The vulnerability has been patched in version 0.5.1, and organizations using OpenClaude should prioritize updating to this version or later to remediate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.1CPE matchmatch criteria | cpe:2.3:a:gitlawb:openclaude:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.