๐Ÿ” CVE Alert

CVE-2026-31975

UNKNOWN 0.0

Cloud CLI WebSocket shell injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from the WebSocket message payload and interpolated into a bash command string without any sanitization, enabling arbitrary OS command execution. A secondary injection vector exists via unsanitized sessionId. This vulnerability is fixed in 1.25.0.

CWE CWE-78
Vendor siteboon
Product claudecodeui
Published Mar 11, 2026
Last Updated Mar 12, 2026
Stay Ahead of the Next One

Get instant alerts for siteboon claudecodeui

Be the first to know when new unknown vulnerabilities affecting siteboon claudecodeui are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

siteboon / claudecodeui
< 1.25.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/siteboon/claudecodeui/security/advisories/GHSA-gv8f-wpm2-m5wr github.com: https://github.com/siteboon/claudecodeui/commit/12e7f074d9563b3264caf9cec6e1b701c301af26 github.com: https://github.com/siteboon/claudecodeui/releases/tag/v1.25.0