deeplink-exploit

Tag

Cards List
#deeplink-exploit

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Lobsters Hottest · 2026-05-13 Cached

A security researcher discovered a Remote Code Execution (RCE) vulnerability in Claude Code caused by improper parsing of deeplink settings, allowing arbitrary command injection via hooks. The issue has been resolved in version 2.1.118.

0 favorites 0 likes
← Back to home

Submit Feedback