1.0.39
4 months ago
6 hours ago
Known vulnerabilities in the @anthropic-ai/claude-code package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@anthropic-ai/claude-code is an Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you. Affected versions of this package are vulnerable to Improper Authorization via unauthorized websocket connections from arbitrary origins. An attacker can access arbitrary files, view the list of files open in the IDE, retrieve selection and diagnostics events, or execute code in limited scenarios by enticing a user to visit a malicious webpage. How to fix Improper Authorization? Upgrade | >=0.2.116 <1.0.24 |