AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73222

HIGH · CVSS 8.8 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in Claude Code Templates allows an unauthenticated attacker to execute arbitrary operating-system commands by exploiting the insecure binding of the server to all interfaces on port 3444 and the unsafe handling of user-controlled input in specific API endpoints. This could lead to the compromise of source code, credentials, and local data, particularly affecting developers who inadvertently access malicious websites while running the Studio server. Organizations using versions prior to 1.29.4 should prioritize patching to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73222
Severity
HIGH
CVSS
8.8
EPSS
0.20%

Original NVD Description

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask(), and POST /api/install-agent passes the agentName request-body field to a child process. The same unsafe agent field path is reachable from /api/execute through checkAndInstallAgent(). These attacker-controlled values reach child_process.spawn() with shell execution enabled, causing Node.js to construct a shell command in which metacharacters are interpreted. An attacker who can reach the port directly, or who convinces a developer running Studio to visit a malicious website, can execute arbitrary operating-system commands with the developer's privileges and compromise source code, credentials, and local data. This issue is fixed in version 1.29.4.