STUPID-2026-0121
Claude Code's read-only command check could be tricked by $IFS and short-flag shell parsing into approving arbitrary code execution
Instruction given
N/A — this is a flaw in Claude Code's own read-only command validator, the layer that is supposed to let an agent run "safe" shell commands without further confirmation, not a task a user asked the agent to perform.
Expected behavior
Claude Code's read-only mode should approve a proposed shell command only if the command genuinely cannot mutate the system or execute arbitrary code — which requires the validator to correctly parse shell syntax, including `$IFS`-based word splitting and short CLI flag forms, rather than pattern-matching on a surface form of the command.
Actual behavior
Errors in how Claude Code's command validator parsed shell commands involving `$IFS` and short CLI flags let a command that would actually execute arbitrary code be classified as read-only and approved without further confirmation. Reliable exploitation required getting attacker-controlled content into the agent's context window — an injection vector — at which point the read-only gate no longer blocked code execution.
Damage
Tracked as CVE-2025-66032 (GHSA-xq4m-mc3c-vvg3, CWE-77: Improper Neutralization of Special Elements in a Command, CVSS v4.0 8.7/High). Reported by security researcher RyotaK of GMO Flatt Security Inc. and published directly on Anthropic's own claude-code security-advisories page. Affected `@anthropic-ai/claude-code` versions before 1.0.93; fixed in 1.0.93 by replacing the command blocklist with an allowlist. Users on Claude Code's standard auto-update received the fix automatically. No in-the-wild exploitation was reported — this was a responsibly disclosed research finding, not an observed attack.
Classification
- Agent
- Claude Code
- Failure mode
- Security Vulnerability
- Root cause
- Logic Error
- Domain
- Security
- Source
- Security Research
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.