HIGH
claude-code-cache-fix: Local code execution via Python triple-quote injection in tools/quota-statusline.sh
Published May 27, 2026
8.6
HIGHCVSS 4.0
EPSS 0.21%
Description
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-controlled field of the payload closes the literal early and lets following bytes execute as Python in the user's Claude Code process. This vulnerability is fixed in 3.5.2.
Affected products
-
- Version >= 3.5.0, < 3.5.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cnighswonger | Claude-Code-Cache-Fix | n/a |
|
- ≥ 3.5.0 · < 3.5.2
No data.
No Red Hat product state for this CVE.
claude-code-cache-fix
npm
Introduced 3.5.0 Fixed 3.5.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | claude-code-cache-fix | 3.5.0 | 3.5.2 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://github.com/advisories/GHSA-g3xq-3gmv-qq8g Advisory
- https://github.com/cnighswonger/claude-code-cache-fix/commit/613e4df30547f3e6baf32d161eddc828f171da17
- https://github.com/cnighswonger/claude-code-cache-fix/issues/108 exploitx_refsource_MISCIssue Tracking
- https://github.com/cnighswonger/claude-code-cache-fix/pull/110 x_refsource_MISCIssue TrackingPatch
- https://github.com/cnighswonger/claude-code-cache-fix/security/advisories/GHSA-g3xq-3gmv-qq8g exploitx_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45136
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-g3xq-3gmv-qq8g | Advisory | |
| https://github.com/cnighswonger/claude-code-cache-fix/commit/613e4df30547f3e6baf32d161eddc828f171da17 | ||
| https://github.com/cnighswonger/claude-code-cache-fix/issues/108 | exploitx_refsource_MISCIssue Tracking | |
| https://github.com/cnighswonger/claude-code-cache-fix/pull/110 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/cnighswonger/claude-code-cache-fix/security/advisories/GHSA-g3xq-3gmv-qq8g | exploitx_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45136 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 27, 2026
Updated Jun 2, 2026
Reserved May 8, 2026
Link CVE-2026-45136
CISA Vulnrichment
GHSA-G3XQ-3GMV-QQ8G Updated Jun 2, 2026