THREAT OPS › Threat News › [GHSA] GHSA-79wm-x847-7cvg (high) — Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
[GHSA] GHSA-79wm-x847-7cvg (high) — Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
GHSA-79wm-x847-7cvg Severity: high CVE: CVE-2026-73222
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
### Summary `npx claude-code-templates --studio` launches "Claude Code Studio", an Express HTTP server (`cli-tool/src/sandbox-server.js`, default port 3444) that binds to **all interfaces** (`0.0.0.0`), sets `Access-Control-Allow-Origin:
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73222cve
- http://127.0.0.1:3444/api/executeurl
- http://127.0.0.1:3444/api/install-agenturl
- https://evil.exampleurl
Original source: https://github.com/advisories/GHSA-79wm-x847-7cvg