-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @anthropic-ai/claude-code | npm | < 1.0.39 | 1.0.39 |
I was unable to find the commit that patches the vulnerability. The advisory does not link to a specific commit, and the tools I have to inspect the repository are not providing the necessary information to pinpoint the exact code changes. Without the patch, I cannot identify the vulnerable functions with high confidence. The get_repo_tags tool failed, which is a critical step in mapping a version to a commit. Also, the publication date of the advisory is in the future, which is unusual and might indicate an issue with the provided data. Given these limitations, I cannot provide a reliable analysis of the vulnerable functions.