Review ID: c3c6a7add4a9Generated: 2026-04-12T02:02:10.894Z
CHANGES REQUESTED
4,720
Total Findings
38
Critical
3,294
High
1,251
Medium
135
Low
6 Tools Deployed
DiamondPlatinumGoldSilverBronzeHR RoastyFree Baseline
Free Baseline Scan — Open-source tools + Hyrex
claude-code-main →
AIAI Threat Analysis
# SECURITY REVIEW: claude-code-main
REAL THREATS
COMMAND INJECTION - CRITICAL
[27] Use of eval() in bash pipe command (line 99)
• Direct eval() usage in bash command processing
• Impact: Arbitrary code execution on host system with full user privileges
• Exploitability: HIGH - If user input reaches this path, instant RCE
• Severity: CRITICAL - This is how systems get owned
[93] Shell command execution via exec() (initReplBridge.ts:562)
• Executing shell commands through exec()
• Impact: Command injection if any unsanitized input reaches this
• Exploitability: Depends on input sanitization upstream (not visible in this scan)
• Severity: HIGH - Potential RCE vector
CREDENTIAL EXPOSURE - CRITICAL
[5] Hardcoded API key (upgrade.tsx:16)
• Generic API key embedded in source code
• Impact: Key compromise, unauthorized API access, potential account takeover
• Exploitability: IMMEDIATE - Anyone with repo access has the key
• Severity: CRITICAL - Credentials in source code = already compromised
[17] Hardcoded API key (datadog.ts:14)
• Datadog API key in source
• Impact: Unauthorized access to monitoring/logging, data exfiltration, log tampering
• Exploitability: IMMEDIATE
• Severity: CRITICAL - Analytics platforms often contain PII and business intelligence
[18] Hardcoded database credentials (datadog.ts:14)
• Default database credentials
• Impact: Direct database access, data breach, data manipulation
• Exploitability: IMMEDIATE if defaults unchanged
• Severity: CRITICAL - Database access = game over
[29] Hardcoded database credentials (diff.ts:31)
• More hardcoded DB credentials
• Impact: Same as above - full database compromise
• Exploitability: IMMEDIATE
• Severity: CRITICAL
INSECURE WEBSOCKET CONNECTIONS - CRITICAL
[1] Insecure WebSocket (replBridgeTransport.ts:189) [2] Insecure WebSocket (workSecret.ts:77) [20] Insecure WebSocket (voiceStreamSTT.ts:136) [28] Insecure WebSocket (mcpServer.ts:64) [31] Insecure WebSocket (ide.ts:795)
• Using ws:// instead of wss://
• Impact: Man-in-the-middle attacks, credential interception, session hijacking
• Exploitability: HIGH on untrusted networks (coffee shops, airports, corporate)
• Severity: CRITICAL - These appear to be core bridge/REPL communications
• Special concern: workSecret.ts name suggests secrets transmitted over plaintext
ATTACK CHAINS
Chain 1: Credential Theft → Lateral Movement
1. Extract hardcoded API keys [5, 17] or DB credentials [18, 29]
2. Access monitoring systems to find additional credentials
3. Access database to extract user data, session tokens, more credentials
4. Pivot to other systems using discovered credentials
Chain 2: MITM → Code Execution
1. MITM insecure WebSocket connections [1, 2, 20, 28, 31]
2. Inject malicious payloads through intercepted bridge communication
3. If injected content reaches eval() [27] or exec() [93], achieve RCE
4. Compromise developer workstation or production system
Chain 3: Repository Access → Full Compromise
1. Attacker gains read access to repository (insider, compromised account, public repo)
2. Extract all hardcoded credentials [5, 17, 18, 29]
3. Use Datadog access to map infrastructure
4. Use DB credentials to extract all data
5. Use API keys to impersonate service
VERDICT
DEPLOY STATUS: DO NOT DEPLOY TO PRODUCTION
This codebase has MULTIPLE CRITICAL SECURITY VULNERABILITIES that create immediate, exploitable attack vectors.
FIX IMMEDIATELY - BLOCKING ISSUES:
1. eval() usage [27] - Replace with safe parsing. This is a loaded gun.
2. All hardcoded credentials [5, 17, 18, 29] - Move to environment variables/secret management BEFORE any deployment. Rotate all exposed keys immediately. These are already compromised if the repo has ever been public or shared.
3. Insecure WebSockets [1, 2, 20, 28, 31] - Force TLS. Non-negotiable for anything beyond localhost development.
FIX URGENTLY:
4. exec() usage [93] - Audit all input paths, implement strict allowlisting, consider safer alternatives.
RISK ASSESSMENT:
• Current State: System is compromised if repo access was ever obtained by unauthorized parties
• Credential Rotation: Required immediately for all embedded secrets
• Production Readiness: NOT READY - Critical vulnerabilities present
• Data Breach Risk: HIGH - Direct database access possible
• RCE Risk: HIGH - Command injection vectors present
• Compliance: FAIL - Hardcoded credentials violate PCI, SOC2, GDPR requirements
HONEST TAKE:
The hardcoded credentials alone are a firing offense. If this repo was ever public, on someone's laptop that got stolen, in a backup, or accessed by a terminated employee - you're already breached. The eval() is sloppy and dangerous. The insecure WebSockets show a lack of security awareness in the development process.
This needs a security audit beyond automated scanning. Fix these critical issues, then get a proper pentest.
4720 raw scanner findings — 38 critical · 3294 high · 1251 medium · 135 low · 2 info
▶ Raw Scanner Output — 4720 pre-cleanup findings
⚠ Pre-Cleanup Report
This is the raw, unprocessed output from all scanner agents before AI analysis. Do not use this to fix issues individually. Multiple agents attack from different angles and frequently report the same underlying vulnerability, resulting in significant duplication. Architectural issues also appear as many separate line-level findings when they require a single structural fix.

Use the Copy Fix Workflow button above to get the AI-cleaned workflow — it deduplicates findings, removes false positives, and provides actionable steps. This raw output is provided for transparency and audit purposes only.
Showing top 1000 of 4720 findings (sorted by severity). Full data available via the review API.
CRITICALSecret detected: generic-api-key
claude-code-main/src/commands/upgrade/upgrade.tsx:16
[AGENTS: baseline:gitleaks]credential_management
Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
Suggested Fix
Remove the secret and rotate the credential. Use environment variables or a secrets manager.
CRITICALSecret detected: generic-api-key
claude-code-main/src/services/analytics/datadog.ts:14
[AGENTS: baseline:gitleaks]credential_management
Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
Suggested Fix
Remove the secret and rotate the credential. Use environment variables or a secrets manager.
CRITICALHardcoded default database credentials
claude-code-main/src/services/analytics/datadog.ts:14
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALHardcoded default database credentials
claude-code-main/src/utils/diff.ts:31
[AGENTS: rules-engine]credentials
**Perspective 1:** Default database credentials are set to weak values: _APP_DB_USER='user', _APP_DB_PASS='password', _APP_DB_ROOT_PASS='rootsecretpassword'. These are common weak passwords that should not be used in production. **Perspective 2:** The environment variable _APP_EXECUTOR_SECRET is set to 'your-secret-key' which appears to be a placeholder/hardcoded value. This secret is used for inter-service communication authentication and having a predictable/default value compromises service-
Suggested Fix
Generate a cryptographically secure random secret using a CSPRNG and set it as the environment variable. For example: `_APP_EXECUTOR_SECRET=$(openssl rand -base64 32)`.
CRITICALUse of eval() — code injection risk
claude-code-main/src/utils/bash/bashPipeCommand.ts:99
[AGENTS: rules-engine]security
eval() usage in claude-code-main/src/utils/bash/bashPipeCommand.ts at line 99 allows arbitrary code execution if input is user-controlled.
Suggested Fix
Replace eval() with a safe alternative (JSON.parse, ast.literal_eval, etc).
CRITICALScala Slick Sql Non Literal
claude-code-main/src/bridge/replBridge.ts:315
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALDetect Insecure Websocket
claude-code-main/src/bridge/replBridgeTransport.ts:189
[AGENTS: baseline:semgrep, rules-engine]security
Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALDetect Insecure Websocket
claude-code-main/src/bridge/workSecret.ts:77
[AGENTS: baseline:semgrep, rules-engine]security
Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALScala Slick Sql Non Literal
claude-code-main/src/commands/review/reviewRemote.ts:217
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/commands/tag/tag.tsx:22
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/ClickableImageRef.tsx:32
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/LogSelector.tsx:432
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/PromptInput/inputPaste.ts:58
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/TagTabs.tsx:126
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/TaskListV2.tsx:373
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/messages/TaskAssignmentMessage.tsx:72
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/components/messages/UserImageMessage.tsx:26
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/history.ts:53
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/hooks/useTaskListWatcher.ts:77
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/ink/styles.ts:16
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/ink/termio/osc.ts:480
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/services/api/promptCacheBreakDetection.ts:658
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALDetect Insecure Websocket
claude-code-main/src/services/voiceStreamSTT.ts:136
[AGENTS: baseline:semgrep, rules-engine]security
Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALScala Slick Sql Non Literal
claude-code-main/src/tools/MCPTool/UI.tsx:399
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/tools/TaskCreateTool/TaskCreateTool.ts:135
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/tools/TaskGetTool/TaskGetTool.ts:110
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/tools/TaskListTool/TaskListTool.ts:105
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/tools/TaskUpdateTool/TaskUpdateTool.ts:380
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/bash/ast.ts:1089
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALDetect Insecure Websocket
claude-code-main/src/utils/claudeInChrome/mcpServer.ts:64
[AGENTS: rules-engine]security
Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/format.ts:223
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALDetect Insecure Websocket
claude-code-main/src/utils/ide.ts:795
[AGENTS: baseline:semgrep, rules-engine]security
Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections.
Suggested Fix
See CWE-319: Cleartext Transmission of Sensitive Information
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/markdown.ts:305
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/queryProfiler.ts:142
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/suggestions/slackChannelSuggestions.ts:199
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/swarm/inProcessRunner.ts:611
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/tasks.ts:848
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CRITICALScala Slick Sql Non Literal
claude-code-main/src/utils/worktree.ts:273
[AGENTS: rules-engine]security
Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using `#$variable` and use `$variable` in `sql"..."` strings instead.
Suggested Fix
See CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
HIGHHardcoded database credentials
claude-code-main/src/services/analytics/datadog.ts:14
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
claude-code-main/src/services/analytics/datadog.ts:14
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHPotential XSS via user input
claude-code-main/src/tools/AskUserQuestionTool/AskUserQuestionTool.tsx:255
[AGENTS: rules-engine]output_encoding
The decrypted private key is directly used without any output encoding, which could lead to XSS if the input is controlled by an attacker.
Suggested Fix
Ensure to sanitize or encode the privateKey before using it in the UI.
HIGHHardcoded database credentials
claude-code-main/src/utils/diff.ts:31
[AGENTS: rules-engine]attack_chains
**Perspective 1:** Database credentials (_APP_DB_USER, _APP_DB_PASS, _APP_DB_ROOT_PASS) are set to default values ('user', 'password', 'rootsecretpassword'). These are weak credentials that could be easily guessed in a production environment. **Perspective 2:** Default database credentials '_APP_DB_USER=user' and '_APP_DB_PASS=password' with root access '_APP_DB_ROOT_PASS=rootsecretpassword' create a critical attack chain: 1) Attacker scans for default Appwrite deployments, 2) Uses default cred
Suggested Fix
Require unique database credentials during installation. Generate strong random passwords and avoid default values. Implement database network isolation to prevent external access.
HIGHHardcoded secrets in production code
claude-code-main/src/utils/diff.ts:31
[AGENTS: rules-engine]api_surface
**Perspective 1:** The configuration requires hardcoded paths for SSL certificates and keys, which can expose sensitive information if not properly secured. **Perspective 2:** SSL certificate and key files must have restrictive permissions to prevent unauthorized access. **Perspective 3:** The configuration requires a hardcoded token for metrics access, which poses a security risk if the configuration file is exposed. **Perspective 4:** The Nginx configuration references SSL certificate paths
Suggested Fix
Ensure that the SSL certificate paths are set via environment variables and that the files have restrictive permissions.
HIGHIncomplete path traversal protection
claude-code-main/src/assistant/sessionHistory.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeApi.ts:45
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeConfig.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeDebug.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeEnabled.ts:6
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeMain.ts:5
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeMessaging.ts:14
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgePermissionCallbacks.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgePointer.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeStatusUtil.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/bridgeUI.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/codeSessionApi.ts:11
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/createSession.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/debugUtils.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/envLessBridgeConfig.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/inboundAttachments.ts:19
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/inboundMessages.ts:7
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/initReplBridge.ts:18
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/jwtUtils.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/pollConfig.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/remoteBridgeCore.ts:55
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/replBridge.ts:10
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/replBridgeHandle.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/replBridgeTransport.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/sessionRunner.ts:6
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/trustedDevice.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/bridge/workSecret.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/buddy/companion.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/buddy/prompt.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/buddy/types.ts:148
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/handlers/agents.ts:13
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/handlers/auth.ts:6
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/handlers/autoMode.ts:6
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/handlers/plugins.ts:8
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/ndjsonSafeStringify.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/print.ts:323
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/remoteIO.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/structuredIO.ts:41
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/HybridTransport.ts:3
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/SSETransport.ts:3
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/SerialBatchEventUploader.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/WebSocketTransport.ts:3
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/WorkerStateUploader.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/ccrClient.ts:6
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/transports/transportUtils.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/cli/update.ts:35
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/add-dir/index.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/add-dir/validation.ts:4
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/advisor.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/agents/index.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/branch/branch.ts:3
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/branch/index.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/bridge-kick.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/bridge/index.ts:2
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/brief.ts:3
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/btw/index.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
HIGHIncomplete path traversal protection
claude-code-main/src/commands/chrome/index.ts:1
[AGENTS: rules-engine]edge_cases
The validateArchiveEntryPath function checks for '..' and '../' but doesn't handle encoded variations like '%2e%2e', '..\', or unicode equivalents.
Suggested Fix
Use path.normalize() and decode URI components before checking, also check for backslashes on Windows.
Note: Fixing issues can create a domino effect — resolving one finding often surfaces new ones that were previously hidden. Multiple scan-and-fix cycles may be needed until you’re satisfied no further issues remain. How deep you go is your call.