In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run Claude Code within it, and the attacker must know or guess a path the victim had already trusted. This issue has been fixed in version 2.1.84.
References
| Link | Resource |
|---|---|
| https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77 | Vendor Advisory |
Configurations
History
12 May 2026, 16:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77 - Vendor Advisory | |
| CPE | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Anthropic claude Code
Anthropic |
|
| CWE | NVD-CWE-noinfo |
05 May 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 21:16
Updated : 2026-05-12 16:21
NVD link : CVE-2026-40068
Mitre link : CVE-2026-40068
CVE.ORG link : CVE-2026-40068
JSON object : View
Products Affected
anthropic
- claude_code
CWE
CWE-20
Improper Input Validation
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')
NVD-CWE-noinfo