A leak of Claude Code reveals critical command injection vulnerabilities. These flaws allow malicious inputs to execute arbitrary code on a user's local machine. Anthropic must now patch these gaps to prevent remote exploitation. Developers should restrict the tool's permissions until a verified security update arrives to protect their local environments.