PT-2026-52680 · Anthropic · Claude-Code
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Claude Code versions 2.1.38 through 2.1.162
Description
Claude Code's worktree handling allows the creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker can overwrite files in the user's home directory, such as
.zshenv, leading to code execution outside of seatbelt sandbox restrictions. This can be achieved through prompt injection if a user clones a malicious repository and runs Claude Code against it. The issue persists even when the tool is used with read-only permissions.Recommendations
Update Claude Code to version 2.1.163.
Exploit
Fix
RCE
Link Following
OS Command Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Claude-Code