claude-code-templates has a security flaw
Claude Code Templates is from davila7. The flaw affects Claude Code Templates before 1.29.4 and has a security flaw.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 1.29.4Fix recorded on Sep 3, 2026
- Affected versions
- 1.29.2 or older
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 0.25% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- Claude Code Templates
How it works
The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask, and POST /api/install-agent passes the agentName request-body field to a child process.
What to do
Check whether the installed Claude Code Templates version is older than 1.29.4.
Follow the Claude Code Templates advisory for a fixed release or mitigation. Then verify the installed version.
Technical details
The source identifies Claude Code Templates as the affected product. Affected ranges: before 1.29.4.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction Required Requires another user to take an action
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- github.com · GHSA-79wm-x847-7cvg vendor advisory
- nvd.nist.gov · CVE-2026-73222 vdb entry
- github.com · CHANGELOG.md (main) NVD GitHub Advisory
- github.com · commit bc4618b NVD GitHub Advisory