@anthropic-ai/claude-code is vulnerable to Authorization Bypass
65
Medium Risk
The Bash and PowerShell permission checkers fail to treat certain crafted inputs as requiring approval. A zsh command hidden inside a [[ ]] regex conditional can run without ever showing the approval prompt, and a Windows PowerShell path that contains quote characters can similarly slip past the check. When those forms are issued through the CLI tools, the expected confirmation in manual or auto permission modes is skipped. The fix makes those Bash/zsh regex-conditional forms and quoted Windows PowerShell paths prompt for permission instead of auto-running.
You are affected if you are using a version that falls within the vulnerable range and rely on Claude Code permission prompts for Bash/zsh commands that use [[ ]] regex conditionals, or for PowerShell tool commands with quoted Windows paths (the PowerShell tool is only present in later releases).
@anthropic-ai/claude-code is vulnerable to Authorization Bypass in versions 0.2.9 - 2.1.220.
Upgrade the @anthropic-ai/claude-code library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant