Skip to content

vulnerability in superdesign project #88

@ankitdn

Description

@ankitdn

While working on superdesign project, I discovered a vulnerability (CVE-2025-66032) in the @anthropic-ai/claude-code package. The issue stems from improper parsing of shell commands, specifically around the Internal Field Separator (IFS) and short command-line flags.

CVE Link
CVE Report

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions