Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jarrodwatts claude Hud
|
|
| CPEs | cpe:2.3:a:jarrodwatts:claude_hud:*:*:*:*:*:claude_code:*:* | |
| Vendors & Products |
Jarrodwatts claude Hud
|
Tue, 19 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jarrodwatts
Jarrodwatts claude-hud |
|
| Vendors & Products |
Jarrodwatts
Jarrodwatts claude-hud |
Mon, 18 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulting in arbitrary code execution on Windows systems. | |
| Title | Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable | |
| Weaknesses | CWE-427 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:16:36.488Z
Reserved: 2026-05-18T19:22:26.747Z
Link: CVE-2026-47092
Updated: 2026-05-19T16:24:56.617Z
Status : Analyzed
Published: 2026-05-18T20:16:40.040
Modified: 2026-06-17T10:54:19.027
Link: CVE-2026-47092
No data.
OpenCVE Enrichment
Updated: 2026-05-19T08:18:41Z