In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run Claude Code within it, and the attacker must know or guess a path the victim had already trusted. This issue has been fixed in version 2.1.84.
References
| Link | Resource |
|---|---|
| https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-05 21:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-40068
Mitre link : CVE-2026-40068
CVE.ORG link : CVE-2026-40068
JSON object : View
Products Affected
anthropic
- claude_code
CWE
CWE-20
Improper Input Validation
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')
NVD-CWE-noinfo