THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-79wm-x847-7cvg (high) — Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)

[GHSA] GHSA-79wm-x847-7cvg (high) — Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)

highgithub_advisoriesPublished 2026-09-03

GHSA-79wm-x847-7cvg Severity: high CVE: CVE-2026-73222

Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)

### Summary `npx claude-code-templates --studio` launches "Claude Code Studio", an Express HTTP server (`cli-tool/src/sandbox-server.js`, default port 3444) that binds to **all interfaces** (`0.0.0.0`), sets `Access-Control-Allow-Origin:

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-79wm-x847-7cvg