{"id":"GHSA-q5hj-mxqh-vv77","summary":"Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution","details":"Claude Code used the git worktree `commondir` file when determining folder trust but did not validate its contents. By crafting a repository with a `commondir` file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in `.claude/settings.json`. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nClaude Code thanks [hackerone.com/masato_anzai](https://hackerone.com/masato_anzai) for reporting this issue.","aliases":["CVE-2026-40068"],"modified":"2026-05-08T15:50:36.976042Z","published":"2026-04-24T16:34:03Z","database_specific":{"github_reviewed_at":"2026-04-24T16:34:03Z","nvd_published_at":"2026-05-05T21:16:23Z","cwe_ids":["CWE-20","CWE-77"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40068"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"affected":[{"package":{"name":"@anthropic-ai/claude-code","ecosystem":"npm","purl":"pkg:npm/%40anthropic-ai/claude-code"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.1.63"},{"fixed":"2.1.84"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q5hj-mxqh-vv77/GHSA-q5hj-mxqh-vv77.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}