


Perceptive Security
SOC/SIEM Consultancy

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasP…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 17:05:49
Source:
nvd.nist.gov
Security Tools,Web Technologies
OpenClaude versions prior to 0.5.1 contain a logic flaw in the bashToolHasPermission() function that allows path traversal attacks to bypass directory restrictions. When sandbox auto-allow is active without explicit deny rules, the function returns allow before evaluating path constraints. This enables attackers to access sensitive files like /etc/passwd using traversal sequences. The vulnerability affects the command line interface for cloud and local model providers. A patch is available in version 0.5.1.
Technical details
Mitigation steps:
Affected products:
OpenClaude
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35570
https://github.com/Gitlawb/openclaude/commit/7002cb302b78ea2a19da3f26226de24e2903fa1d
https://github.com/Gitlawb/openclaude/security/advisories/GHSA-m6rx-7pvw-2f73
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
