CVE-2026-47092: Jarrodwatts Claude Hud
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulting in arbitrary code execution on Windows systems.
Affected products
- Jarrodwatts Claude Hud: up to and including 0.0.12
Published 2026-05-18. Last modified 2026-07-14.