
CVSS 9.8 Command Injection in Claude-Hovercraft - Another AI Tool RCE Joins the Pile
ZDI-26-124 discloses a critical command injection vulnerability in the claude-hovercraft tool's executeClaudeCode function, scoring CVSS 9.8 with no authentication required.

