CVE-2026-55607
published 2026-06-29CVE-2026-55607: Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.55%
44.8th percentile
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it. This vulnerability is fixed in 2.1.163.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| anthropic-ai | claude-code | >= 2.1.38 < 2.1.163 | 2.1.163 |
| anthropic | claude_code | >= 2.1.38 < 2.1.163 | 2.1.163 |
| anthropics | claude-code | — | — |
| openshift-lightspeed | lightspeed-agentic-sandbox-rhel9 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
ghsa·2026-07-24
CVE-2026-55607 [HIGH] CWE-22 Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it.
Users on standard Claude Code auto-update have received this fix automatically. Users performing manual updates are advised to update to the lates
VulDB
Anthropic claude-code up to 2.1.162 Repository path traversal (GHSA-7835-87q9-rgvv)
vuldb·2026-07-04·CVSS 8.8
CVE-2026-55607 [HIGH] Anthropic claude-code up to 2.1.162 Repository path traversal (GHSA-7835-87q9-rgvv)
A vulnerability, which was classified as critical, was found in Anthropic claude-code up to 2.1.162. Affected by this issue is some unknown functionality of the component Repository Handler. The manipulation results in path traversal.
This vulnerability was named CVE-2026-55607. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
Red Hat
Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
vendor_redhat·2026-06-29·CVSS 8.8
CVE-2026-55607 [HIGH] CWE-59 Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it. This vulnerability is fixed in 2.1.163.
A flaw was found in Clau
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55607 Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
bugzilla·2026-06-29·CVSS 8.8
CVE-2026-55607 [HIGH] CVE-2026-55607 Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
CVE-2026-55607 Claude Code: @anthropic-ai/claude-code: Claude Code: Arbitrary code execution through git directory confusion
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it. This vulnerability is fixed in 2.1.163.
Hackernews
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
blogs_hackernews·2026-09-02·CVSS 7.3
CVE-2026-19592 [HIGH] Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.
The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive as files with its .git directory intact, which a shared archive, a shared drive, a sync folder, or a USB stick preserves, whereas an ordinary c
2026-06-29
Published