claude-code-templates has a security flaw

Published September 3, 2026 CVE-2026-73222

Claude Code Templates is from davila7. The flaw affects Claude Code Templates before 1.29.4 and has a security flaw.

Severity
HighCVSS 3.1 · 8.8
Fix
Fixed in 1.29.4Fix recorded on Sep 3, 2026
Affected versions
1.29.2 or older
Weakness
CWE-78OS Command Injection
Exploit likelihood
0.25% in 30 daysEPSS, higher than 16% of known flaws
Affects
Claude Code Templates

How it works

The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask, and POST /api/install-agent passes the agentName request-body field to a child process.

What to do

Check whether the installed Claude Code Templates version is older than 1.29.4.

Follow the Claude Code Templates advisory for a fixed release or mitigation. Then verify the installed version.

Technical details

The source identifies Claude Code Templates as the affected product. Affected ranges: before 1.29.4.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction Required Requires another user to take an action
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Open in FIRST.org calculator