CVE-2026-73222 | davila7 claude-code-templates up to 1.29.3 Studio sandbox-server.js child_process.spawn prompt/agentName os command injection
A vulnerability categorized as critical has been discovered in davila7 claude-code-templates up to 1.29.3. This vulnerability affects the function child_process.spawn of the file cli-tool/src/sandbox-server.js of the component Studio. Such manipulation of the argument prompt/agentName leads to os command injection.
This vulnerability is traded as CVE-2026-73222. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More