Last seen May 29, 2026

Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118)

Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri

Why This Matters

Publisher reporting describes a security event affecting may. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether may is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

May 29, 2026 12:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

AnthropicMicrosoftOpenAIChatGPTClaudeClaude Code

Timeline

  • Incident first seen
    May 18, 2026 12:30

    BugSkan first recorded this incident.

  • Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) - Pasquale Pillitteri
    May 18, 2026 12:30

    news.google.com ยท Vulnerability

  • ChatGPT Vulnerability Allows Threat Actors To Turn Web Pages Into Phishing Payloads - LinkedIn
    May 29, 2026 12:30

    news.google.com ยท News

  • Latest observed development
    May 29, 2026 12:30

    Most recent source or update associated with this incident.

Sources

Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) - Pasquale Pillitteri

news.google.com ยท May 18, 2026 12:30

Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri

Open publisher source
ChatGPT Vulnerability Allows Threat Actors To Turn Web Pages Into Phishing Payloads - LinkedIn

news.google.com ยท May 29, 2026 12:30

ChatGPT Vulnerability Allows Threat Actors To Turn Web Pages Into Phishing Payloads LinkedIn

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence