CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions

0
12

A critical vulnerability in older versions of the Claude Code for Visual Studio Code (VS Code) and other IDE extensions allowed malicious websites to connect to unauthenticated local WebSocket servers, potentially enabling remote command execution – Read more