Cloudcli provides a cloud command-line interface tool; its modest vulnerability footprint centers on OS command injection and code injection flaws that reflect the product's need to parse and execute user-supplied input. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudcli over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31975CRITICAL Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projec | Mar 11, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-31861HIGH Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell co | Mar 11, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-31862HIGH Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() wi | Mar 11, 2026 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudcli.
Media articles that mention a CVE ID that affects a product developed by Cloudcli — matched by CVE ID, not by vendor name.