PT-2026-26297 · Anthropic · Claude-Code

·

CVE-2026-33068

·

Published

2026-03-19

·

Updated

2026-07-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 2.1.53
Description Claude Code is an agentic coding tool that experienced a loading order issue in its settings loader. The software resolved the permission mode from settings files, such as the repository-controlled .claude/settings.json, before determining if the workspace trust confirmation dialog should be displayed. A malicious repository could set the permissions.defaultMode variable to bypassPermissions within its committed .claude/settings.json file, causing the trust dialog to be silently skipped upon the first time the repository is opened. This allows a user to be placed into a permissive mode without explicit consent, potentially enabling an attacker-controlled repository to achieve tool execution, file system access, and command execution.
Recommendations Update to version 2.1.53 or later. As a temporary mitigation, review the .claude/settings.json file in unfamiliar repositories to ensure the permissions.defaultMode variable is not set to bypassPermissions before opening them.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33068
GHSA-MMGP-WC2J-QCV7

Affected Products

Claude-Code