@anthropic-ai/claude-code@1.0.9 vulnerabilities

Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.

  • latest version

    1.0.39

  • latest non vulnerable version

  • first published

    4 months ago

  • latest version published

    6 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @anthropic-ai/claude-code package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Authorization

    @anthropic-ai/claude-code is an Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.

    Affected versions of this package are vulnerable to Improper Authorization via unauthorized websocket connections from arbitrary origins. An attacker can access arbitrary files, view the list of files open in the IDE, retrieve selection and diagnostics events, or execute code in limited scenarios by enticing a user to visit a malicious webpage.

    How to fix Improper Authorization?

    Upgrade @anthropic-ai/claude-code to version 1.0.24 or higher.

    >=0.2.116 <1.0.24