BlockBeats News, January 8 — Security researcher 23pds from the Slow Fog team reposted a report by researcher Adam Chester, revealing a privilege escalation and command execution vulnerability in Anthropic’s Claude Code. Attackers can execute commands without user authorization. The vulnerability is assigned CVE-2025-64755, and a related PoC has been made public. The issue is said to be similar to a related vulnerability disclosed earlier in the Cursor tool.
23pds states that phishing hackers have already exploited the related vulnerability to attack crypto users.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Claude Code high-risk privilege escalation vulnerability exploited by hackers to attack encrypted users
BlockBeats News, January 8 — Security researcher 23pds from the Slow Fog team reposted a report by researcher Adam Chester, revealing a privilege escalation and command execution vulnerability in Anthropic’s Claude Code. Attackers can execute commands without user authorization. The vulnerability is assigned CVE-2025-64755, and a related PoC has been made public. The issue is said to be similar to a related vulnerability disclosed earlier in the Cursor tool.
23pds states that phishing hackers have already exploited the related vulnerability to attack crypto users.