### 漏洞概述 **漏洞名称**: Local code execution via Python triple-quote injection in tools/quota-statusline.sh **CVE ID**: CVE-2024-0136 **严重程度**: High **描述**: Claude Code 的 `tools/quota-statusline.sh` 脚本(在 v…
### 漏洞概述 **标题**: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption **描述**: `src/pad.c` 中存在三个与文件系统路径处理相关的弱点,用于一次性密码(one-time pad): 1. **H-4 — Pad dire…