PatchSiren cyber security CVE debrief
CVE-2026-47091 jarrodwatts CVE debrief
A path traversal vulnerability in Claude HUD through version 0.0.12 allows local attackers with low privileges to read arbitrary files readable by the process. The vulnerability stems from insufficient validation of the `transcript_path` parameter supplied via stdin JSON. Additionally, accessed file metadata is written to a persistent cache file with overly permissive permissions, creating a forensic record that survives process termination. The issue was patched in commit 234d9aa. The CVSS 4.0 vector indicates local attack vector, low attack complexity, low privileges required, and no user interaction needed, with low confidentiality impact.
- Vendor
- jarrodwatts
- Product
- claude-hud
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-07-14
Who should care
Organizations and developers using Claude HUD for AI-assisted development workflows, particularly in multi-user or shared environments where process file system permissions may expose sensitive configuration files, credentials, or source code. Security teams should prioritize patching in development environments where Claude HUD processes may have elevated file access.
Technical summary
The vulnerability exists in Claude HUD versions through 0.0.12 where the `transcript_path` parameter from stdin JSON is not properly validated before use in file operations. This allows path traversal sequences to access files outside intended directories. The application also writes file metadata to a persistent cache with insufficient permission restrictions, preserving evidence of file access even after process termination. The attack requires local access and low privileges but no user interaction.
Defensive priority
medium
Recommended defensive actions
- Upgrade Claude HUD to version 0.0.13 or later containing commit 234d9aa
- Review and restrict file system permissions for the Claude HUD process to minimize accessible files
- Audit and remove any existing cache files that may contain forensic records of prior file access
- Implement input validation for all JSON parameters received via stdin, particularly path-related fields
- Consider sandboxing or containerizing Claude HUD to limit filesystem exposure
- Monitor for anomalous file access patterns in environments running unpatched versions
Evidence notes
Vulnerability disclosed via Vulncheck advisory with references to GitHub commit, issue, and pull request. Patch commit 234d9aad919b51326a43bcf90b45ae35c23afc30 confirms remediation. CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) identified as primary weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47091 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47091
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47091 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47091
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/jarrodwatts/claude-hud/commit/234d9aad919b51326a43bcf90b45ae35c23afc30
-
Source reference
Unverified legacy reference
URL: https://github.com/jarrodwatts/claude-hud/issues/485
-
Source reference
Unverified legacy reference
URL: https://github.com/jarrodwatts/claude-hud/pull/487
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/claude-hud-path-traversal-via-transcript-path
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.