STUPID-2026-0121

Claude Code's read-only command check could be tricked by $IFS and short-flag shell parsing into approving arbitrary code execution

7.6high
December 3, 2025Verified
  1. Instruction given

    N/A — this is a flaw in Claude Code's own read-only command validator, the layer that is supposed to let an agent run "safe" shell commands without further confirmation, not a task a user asked the agent to perform.

  2. Expected behavior

    Claude Code's read-only mode should approve a proposed shell command only if the command genuinely cannot mutate the system or execute arbitrary code — which requires the validator to correctly parse shell syntax, including `$IFS`-based word splitting and short CLI flag forms, rather than pattern-matching on a surface form of the command.

  3. Actual behavior

    Errors in how Claude Code's command validator parsed shell commands involving `$IFS` and short CLI flags let a command that would actually execute arbitrary code be classified as read-only and approved without further confirmation. Reliable exploitation required getting attacker-controlled content into the agent's context window — an injection vector — at which point the read-only gate no longer blocked code execution.

  4. Damage

    Tracked as CVE-2025-66032 (GHSA-xq4m-mc3c-vvg3, CWE-77: Improper Neutralization of Special Elements in a Command, CVSS v4.0 8.7/High). Reported by security researcher RyotaK of GMO Flatt Security Inc. and published directly on Anthropic's own claude-code security-advisories page. Affected `@anthropic-ai/claude-code` versions before 1.0.93; fixed in 1.0.93 by replacing the command blocklist with an allowlist. Users on Claude Code's standard auto-update received the fix automatically. No in-the-wild exploitation was reported — this was a responsibly disclosed research finding, not an observed attack.

Claude Code's read-only permission mode exists so the agent can run commands it judges non-mutating — reads, searches, status checks — without stopping to ask the user first. Security researcher RyotaK of GMO Flatt Security Inc. found that the validator behind that gate mis-parsed shell syntax involving `$IFS` (the shell's field-separator variable, usable in place of a literal space) and certain short CLI flag forms, which made it possible to construct a command that the validator judged read-only but that, once actually run, executed arbitrary code. The read-only check was pattern-matching a surface form of the command rather than correctly parsing what the shell would do with it. Anthropic's own advisory is explicit about the precondition: "reliably exploiting this requires the ability to add untrusted content into a Claude Code context window" — this is a bypass that becomes dangerous once combined with a prompt-injection vector (a malicious file, issue, or tool output the agent reads), not something a user triggers directly. Tracked as CVE-2025-66032 (GHSA-xq4m-mc3c-vvg3, CWE-77, CVSS v4.0 8.7/High), the flaw affected `@anthropic-ai/claude-code` versions before 1.0.93 and was fixed in that release by replacing the validator's blocklist approach with an allowlist — a structural fix rather than a patch for the specific parsing bug, since a blocklist of "which commands aren't safe" is exactly the kind of check this bypass exploited. Users on Claude Code's standard auto-update channel received the fix without action; no in-the-wild exploitation of the flaw was reported before the fix shipped.

Classification

Root cause
Logic Error
Domain
Security

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.