Skip to content

CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context

HERMES

HERMES THREAT SCORE & OPERATIONAL EXPLOITABILITY

Target: Claude Code CLI Shell Command Formatter and Approval Loop
Confidence: 96%
92 / 100
HIGH

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 17 / 20
Weaponization 18 / 20
Exposure 18 / 20
Prevalence 18 / 20
Impact 20 / 20
Exploit Maturity 18 / 20
Attack Chain Potential 20 / 20
โš–๏ธ Divergence & Operational Rationale

CVSS v3.1 rates this vulnerability at 8.7. Hermes Threat Score rates it at 92 (HIGH) taking into account active exploit telemetry, critical AI workflow dependencies, and immediate host privilege escalation.

HASS

HASS AGENTIC SEVERITY & AUTONOMOUS RISK EVALUATION

Target: Claude Code Agentic CLI Tool & Memory Architecture
Confidence: 95%
95 / 100
CRITICAL

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 20 / 20
Tool Access 20 / 20
Privilege 19 / 15
Persistence 18 / 15
External Impact 20 / 15
Propagation 18 / 15
โš–๏ธ Divergence & Operational Rationale

Agentic security failure classified under AAP-002 (Indirect Context Injection) -> AAP-007 (Tool Approval Bypass). The flaw collapses trust boundaries between autonomous model reasoning loops and operating system execution tiers.

๐Ÿ•ธ๏ธ Connected Knowledge Graph & Provenance

CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted ContextVULNERABILITY

Connected Nodes: 4
Active Relationships (Outgoing)
→ affectsPRODUCTClaude Code Agentic CLI
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

๐Ÿ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Claude Code Agentic CLI documented in Hermes dossier.”

Supporting Verified Evidence:
→ exploitsAGENTIC ATTACK_PATTERNAAP-002: Indirect Context Injection
92% VERY_HIGH

Adversary embeds covert payload instructions into retrieved external data (web pages, repositories, emails) that subvert model planning when parsed by autonomous agents.

๐Ÿ” Why is this related? (Evidence & Provenance)

“CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-002.”

Supporting Verified Evidence:
→ exploitsAGENTIC ATTACK_PATTERNAAP-007: Autonomous Cascading RCE
92% VERY_HIGH

Cascading multi-stage attack chaining context injection, autonomous loop planning, and un-sandboxed execution sinks to achieve persistent root shell compromise on host machines.

๐Ÿ” Why is this related? (Evidence & Provenance)

“CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-007.”

Supporting Verified Evidence:
→ usesATTACK TECHNIQUET1059: Command and Scripting Interpreter
90% VERY_HIGH

Adversaries abuse command and script interpreters (Bash, Python, PowerShell) to execute arbitrary commands.

๐Ÿ” Why is this related? (Evidence & Provenance)

“Attack execution telemetry aligns with MITRE ATT&CK technique T1059.”

Supporting Verified Evidence:

Claude Code Agentic CLI is widely deployed in production environments to support large language model orchestration, data pipelines, and agentic workflows. CVE-2025-54795 represents a significant threat to enterprise infrastructure:

AttributeTechnical SpecificationOperational Ramification
Vulnerability IDCVE-2025-54795Tracked in Hermes Knowledge Graph
Affected SystemClaude Code Agentic CLIAnthropic
Vulnerable ComponentClaude Code CLI Shell Command Formatter and Approval LoopInput processing & execution gate
Exploit VectorNetwork / Local Untrusted ContextCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV StatusMonitored / High Weaponization PotentialUrgent patching prioritization
Attack TechniquesT1059.004 (Unix Shell), T1204.002 (Malicious File / Context Manipulation)MITRE ATT&CK Framework
Agentic Attack PatternAAP-002 (Indirect Context Injection) -> AAP-007 (Tool Approval Bypass)Hermes Agentic Security Catalog

The vulnerability stems from insufficient validation and flawed isolation boundaries in Claude Code CLI Shell Command Formatter and Approval Loop:

[ Attacker Payload / Untrusted Input ]
โ”‚
โ–ผ
[ Ingress: Claude Code CLI Shell Command Formatter and Approval Loop ]
โ”‚ (Missing Canonical Sanitization / Dangerous Evaluation)
โ–ผ
[ Execution Tier: Host OS / Runtime Subprocess ]
โ”‚
โ–ผ
[ Impact: Arbitrary Code Execution / Credential Exfiltration ]

When processing requests, the vulnerable logic failed to enforce strict allowlisting or canonical path validation, permitting direct execution or unauthorized file access.


Defenders must understand how threat actors weaponize CVE-2025-54795 in real-world intrusion operations:

  1. Target Identification & Probing: Adversaries discover exposed instances through version fingerprinting or metadata scraping.
  2. Payload Delivery: A crafted request containing the exploit payload is transmitted to the vulnerable endpoint (Claude Code CLI Shell Command Formatter and Approval Loop).
  3. Execution & Breakout: The application executes the payload under the process user permissions, escaping intended sandboxes.
  4. Post-Exploitation & Pivot: The attacker harvests LLM API keys, establishes persistence, or moves laterally into connected cloud storage.

Security Operations Centers (SOC) and incident response teams can deploy the following detection signatures:

title: Suspicious Execution from Claude Code Agentic CLI Subprocess (CVE-2025-54795)
status: experimental
description: Detects abnormal process execution or file creation spawned by Claude Code Agentic CLI
references:
- https://codex.hermes-cyber.com/cve/2025/cve-2025-54795/
author: Hermes Cyber Intelligence
logsource:
category: process_creation
product: linux
detection:
selection:
ParentImage|endswith:
- '/python'
- '/node'
- '/langflow'
- '/flowise'
Image|endswith:
- '/sh'
- '/bash'
- '/curl'
- '/wget'
condition: selection
falsepositives:
- Legitimate administrative tooling
level: high

To mitigate exposure to CVE-2025-54795:

  1. Immediate Upgrade: Upgrade to Claude Code 1.0.20 or later immediately.
  2. Network Isolation: Restrict access to administrative interfaces and API listeners via internal VPN or Zero-Trust Network Access (ZTNA).
  3. Container Sandboxing: Run workloads with non-root service accounts, read-only root filesystems, and strict seccomp/AppArmor profiles.
  4. Credential Rotation: Rotate all LLM provider API keys, database credentials, and cloud secrets that resided in the environment.