> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions

[SOURCE] Datadog Security Labs [DATE: 26/08/2025 00:00] [LANGUAGE: EN]
A critical vulnerability in older versions of the Claude Code for Visual Studio Code (VS Code) and other IDE extensions allowed malicious websites to connect to unauthenticated local WebSocket servers, potentially enabling remote command execution
[messages.read_original_source] →