Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4524-x6pc-rr9x

Опубликовано: 18 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 3.3

Описание

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.

EPSS

Процентиль: 3%
0.00126
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.3
nvd
4 месяца назад

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.

EPSS

Процентиль: 3%
0.00126
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-22