Description
Download: cve_claudecodeui_submission_v2.zip
Recommendation
Update the @siteboon/claude-code-ui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.24.0
- Patched version(s): 1.25.0
References
Could your website be exposed too?
SmartScanner can check your website for @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes - CVE-2026-31861
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- lodash vulnerable to Code Injection via `_.template` imports key names - lodash-amd - CVE-2026-4800
- lodash vulnerable to Code Injection via `_.template` imports key names - lodash-es - CVE-2026-4800
You might also like:
See something that needs correcting? Let us knowUpdated March 11, 2026


