Vulnerabilities/

claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh

Severity:
High

Description

tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code’s hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-controlled field of the payload closes the literal early and lets following bytes execute as Python in the user’s Claude Code process.

Recommendation

Update the claude-code-cache-fix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
claude-code-cache-fix
Anything's wrong? Let us know Last updated on May 13, 2026