{"id":"GHSA-g3xq-3gmv-qq8g","summary":"claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh","details":"## Summary\n\n`tools/quota-statusline.sh` (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A `'''` byte sequence in any user-controlled field of the payload closes the literal early and lets following bytes execute as Python in the user's Claude Code process.\n\n## Affected versions\n\n- v3.5.0\n- v3.5.1\n\n## Patched versions\n\n- v3.5.2\n\n## Affected configurations\n\nUsers who wired `tools/quota-statusline.sh` into Claude Code's `statusLine` configuration. The v3.5.0 README explicitly recommends this setup, so most users on v3.5.0/v3.5.1 with the recommended setup are affected.\n\n## Attack chain\n\nClaude Code's statusline hook payload reflects user-controlled paths (`cwd`, `workspace.current_dir`, `workspace.project_dir`, `transcript_path`). Apostrophes are legal in POSIX filesystem paths.\n\n1. A hostile directory name containing `'''+payload+'''` lands on disk via any normal vector — `git clone`, archive extraction, npm package, downloaded zip, etc.\n2. The victim has the recommended `tools/quota-statusline.sh` wired into their CC `statusLine` config.\n3. The victim `cd`s anywhere a hostile path is reachable.\n4. CC fires the statusline hook on every redraw. The Python literal closes early. The injected bytes execute as Python in the user's process.\n\n## Severity\n\nLocal code execution at user privilege. Persistent re-fire on every statusline redraw. No user interaction beyond `cd`-ing into the hostile path. The user's shell, CC session, files, SSH keys, and any locally-accessible credentials are reachable from the executed code.\n\n## Vulnerable pattern\n\n```sh\ninput=$(cat)\nresult=$(python3 -c \"\n    stdin_data = json.loads('''$input''') if '''$input''' else {}\n\")\n```\n\n## Fix\n\nCapture stdin in bash, export to env, and pipe the Python source through a single-quoted heredoc (`\u003c\u003c'PYEOF'`). Single-quoting disables ALL bash interpolation inside the body. Python reads the JSON via `os.environ.get('CC_INPUT')`, where the bytes are inert at every layer.\n\n```sh\nCC_INPUT=$(cat)\nexport CC_INPUT\n\npython3 \u003c\u003c'PYEOF' 2\u003e/dev/null\nimport os, json\ntry:\n    cc_input = json.loads(os.environ.get('CC_INPUT') or '{}')\nexcept Exception:\n    cc_input = {}\n# ...\nPYEOF\n```\n\n## Workarounds\n\nUntil upgrading to v3.5.2:\n\n- Disable the statusline by removing the `statusLine` entry from `~/.claude/settings.json`, or\n- Replace `tools/quota-statusline.sh` with a script that does NOT pass stdin through `python3 -c \"...\"` (a heredoc + env var rewrite is safe)\n\n## Credit\n\nReported by Jakob Linke (@schuay) via GitHub issue [#108](https://github.com/cnighswonger/claude-code-cache-fix/issues/108).\n\n## Timeline\n\n- 2026-05-07 — reported (#108)\n- 2026-05-07 — confirmed, fix implemented (#110)\n- 2026-05-07 — v3.5.2 published","aliases":["CVE-2026-45136"],"modified":"2026-06-09T00:00:19.227252611Z","published":"2026-05-13T15:31:41Z","database_specific":{"nvd_published_at":"2026-05-27T21:16:18Z","cwe_ids":["CWE-78","CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-13T15:31:41Z"},"references":[{"type":"WEB","url":"https://github.com/cnighswonger/claude-code-cache-fix/security/advisories/GHSA-g3xq-3gmv-qq8g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45136"},{"type":"WEB","url":"https://github.com/cnighswonger/claude-code-cache-fix/issues/108"},{"type":"WEB","url":"https://github.com/cnighswonger/claude-code-cache-fix/pull/110"},{"type":"WEB","url":"https://github.com/cnighswonger/claude-code-cache-fix/commit/613e4df30547f3e6baf32d161eddc828f171da17"},{"type":"PACKAGE","url":"https://github.com/cnighswonger/claude-code-cache-fix"}],"affected":[{"package":{"name":"claude-code-cache-fix","ecosystem":"npm","purl":"pkg:npm/claude-code-cache-fix"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.5.0"},{"fixed":"3.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g3xq-3gmv-qq8g/GHSA-g3xq-3gmv-qq8g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}