BlockBeats News, January 8th, SlowMist security researcher 23pds retweeted researcher Adam Chester's report, revealing a privilege escalation and command execution vulnerability in Anthropic's Claude Code, allowing attackers to execute commands without user authorization, vulnerability ID CVE-2025-64755, with a related PoC already disclosed. The issue was said to be similar to a previously disclosed similar vulnerability in the Cursor tool.
23pds stated that phishing hackers have been exploiting the vulnerability to attack cryptocurrency users.
