What is CVE-2026-73222?
CVE-2026-73222: A critical vulnerability in Claude Code Templates CLI tool where the --studio server binds to all interfaces, requires no authentication, and permits CORS. Immediate update to version 1.29.4 is required.
Azərbaycanca: CVE-2026-73222: Claude Code Templates CLI alətində kritik səhvdir. --studio serveri bütün interfeyslərə bağlanır, autentifikasiya tələb etmir və CORS icazəsi verir. Təcili olaraq 1.29.4 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Why is CVE-2026-73222 considered critical?
CVE-2026-73222 is critical because in the Claude Code Templates CLI tool, the `--studio` server binds to all interfaces, requires no authentication, and permits CORS, potentially allowing unauthorized remote access.
What should I do to protect against CVE-2026-73222?
To protect against CVE-2026-73222, you must immediately update the Claude Code Templates CLI tool to version 1.29.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.