CVE-2025-58764 is a critical vulnerability affecting Anthropic Claude Code versions prior to 1.0.105, allowing for a bypass of the confirmation prompt to execute untrusted commands due to an error in command parsing. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and can lead to complete compromise of confidentiality, integrity, and availability if untrusted content can be introduced. While the EPSS score is low, indicating a low probability of exploitation, there is currently no public exploit code available, nor is there significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.105CPE matchmatch criteria | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.