Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118)
Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri
What Happened
Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri
Why This Matters
Publisher reporting describes a security event affecting may. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether may is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Exposure
Exposure unknown
May 29, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
May 18, 2026 12:30BugSkan first recorded this incident.
-
Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) - Pasquale Pillitteri
May 18, 2026 12:30news.google.com ยท Vulnerability
-
ChatGPT Vulnerability Allows Threat Actors To Turn Web Pages Into Phishing Payloads - LinkedIn
May 29, 2026 12:30news.google.com ยท News
-
Latest observed development
May 29, 2026 12:30Most recent source or update associated with this incident.
Sources
news.google.com ยท May 18, 2026 12:30
Claude Code RCE: claude-cli:// Deeplink Vulnerability Allows Arbitrary Command Execution (Patch 2.1.118) Pasquale Pillitteri
Open publisher sourcenews.google.com ยท May 29, 2026 12:30
ChatGPT Vulnerability Allows Threat Actors To Turn Web Pages Into Phishing Payloads LinkedIn
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.