HarborGuard / CVE
Back to search
HIGHCVE-2026-47092Published Modified CNA VulnCheck

CVE-2026-47092: Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulting in arbitrary code execution on Windows systems.

Metrics

CVSS v4.0
7.3
Severity
HIGH
Fixed in
234d9aad919b51326a43bcf90b45ae35c23afc30
Affected Products
1

Fix available

234d9aad919b51326a43bcf90b45ae35c23afc30
Patch commits
Affected packages
  • jarrodwatts / claude-hud
    ≤ 0.0.12
    Fixed in 234d9aad919b51326a43bcf90b45ae35c23afc30
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N