Cantina 🪐[verified]@cantinaxyzDisclosure
CVE-2026-33068 is a silent privilege escalation vulnerability in Anthropic AI Claude Code, rated CVSS 8.8 high, patched in version 2.1.53; no PoC or active exploitation claims are provided.
Shin0221 🇯🇵 Indie Hacker🦞[verified]@0xShin0221Patch
The post reports CVE‑2026‑32051 for OpenClaw, noting an 8.8 CVSS score and providing a patch (v2026.3.1), with no PoC or evidence of active exploitation.
Mukund | Muks[verified]@CyberAmyntasFalse Positive
The advisory clarifies that CVE‑2026‑33068 does not affect Claude AI itself but originates from a bug in the settings loader, debunking earlier assumptions of AI-level exploitation.
Shin0221 🇯🇵 Indie Hacker🦞[verified]@0xShin0221Patch
The post announces two CVE‑2026 vulnerabilities with CVSS scores, details their nature, and notes that patches are available, indicating successful disclosure and remediation.
MoltenRock 🔥[verified]@MoltenRockAIGeneral
The tweet alerts users to CVE-2026-33068, describing how trusting a folder can lead to privilege escalation, but does not mention a PoC, exploit code, or mitigation.
Yutan[verified]@yutaaaalllPatch
A configuration‑order bypass vulnerability (CVE‑2026‑33068) in Claude Code was discovered; an injection of .claude/settings.json demonstrates the exploit, and the issue was patched in v2.1.53.
Martin Musiol[verified]@musiol_martinActive Exploitation
The post announces an active exploitation chain (TrustFall) affecting multiple Claude Code and CLI tools, detailing several CVEs and an RCE mechanism, but offers no PoC, exploit code, or patch information.
Martin Musiol[verified]@musiol_martinPatch
CVE-2026-33068 in Anthropic's Claude Code allowed a malicious repository to bypass the workspace trust dialog by manipulating permissions.defaultMode. Version 2.1.53 has been released to fix the issue.