- 6th April 2026
Three shell injection sinks in Claude Code CLI chain from environment variable control to HTTP credential exfiltration, confirmed on v2.1.91 with timestamped callback evidence. The vendor says it is by design.
Francesco Cipollone