Skip to content
Critical RCE Vulnerability in Claude Code CLI Exposed via Malicious Deeplinks

Critical RCE Vulnerability in Claude Code CLI Exposed via Malicious Deeplinks

First seen 18 May 2026, 06:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 19, 2026 at 06:16 UTC
  • A critical RCE vulnerability in Claude Code CLI was disclosed, affecting user systems.
  • The flaw allowed execution of arbitrary commands via crafted deeplink URLs.
  • The issue has been patched in version 2.1.118; users are urged to update immediately.

A critical Remote Code Execution (RCE) vulnerability was discovered in Anthropic's Claude Code CLI, allowing attackers to execute arbitrary commands on a victim's machine through specially crafted deeplinks. Identified by security researcher Joernchen, the flaw stemmed from insecure CLI flag parsing, which was exploited by injecting command fragments into deeplink URLs. This vulnerability, now patched in version 2.1.118, highlights the risks associated with convenience features in developer tools when input validation is inadequate. The issue was documented in various reports, emphasizing the need for secure handling of deeplink inputs. Security teams are advised to update to the patched version and review their CLI security practices. The vulnerability underscores a recurring class of issues in AI development tools, where traditional software flaws can lead to severe security risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 125d ago How this analysis works

Timeline

2026-05-18
RCE vulnerability disclosed
Joernchen reported a critical RCE flaw in Claude Code CLI, enabling command execution via deeplinks.
Neuraltrust.Ai
2026-05-18
Vulnerability patched
Anthropic released version 2.1.118 of Claude Code, fixing the RCE vulnerability.
Letsdatascience
2026-05-18
Public awareness raised
Multiple cybersecurity outlets reported on the vulnerability, emphasizing its implications for developer tools.
Gbhackers

More articles in this cluster (4)

Following this threat?

Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed