PT-2026-52680 · Anthropic · Claude-Code

·

CVE-2026-55607

·

Published

2026-06-26

·

Updated

2026-09-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions 2.1.38 through 2.1.162
Description Claude Code's worktree handling allows the creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker can overwrite files in the user's home directory, such as .zshenv, leading to code execution outside of seatbelt sandbox restrictions. This can be achieved through prompt injection if a user clones a malicious repository and runs Claude Code against it. The issue persists even when the tool is used with read-only permissions.
Recommendations Update Claude Code to version 2.1.163.

Exploit

Fix

RCE

Link Following

OS Command Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55607
GHSA-7835-87Q9-RGVV

Affected Products

Claude-Code