Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMService
Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
Claude Code Has Permission Deny Bypass Through Symbolic Links
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
Claude Code has a Command Injection in find Command Bypasses User Approval Prompt
Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Showing 1 - 20 of 1,000+ results