CVE-2026-33068Patch(anthropic / claude_code)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch anthropic claude_code systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A malicious repository could set permissions.defaultMode to bypassPermissions in its committed .claude/settings.json, causing the trust dialog to be silently skipped on first open. This allowed a user to be placed into a permissive mode without seeing the trust confirmation prompt, making it easier for an attacker-controlled repository to gain tool execution without explicit user consent. This issue has been patched in version 2.1.53.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-807

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 5 classified signals
  • General: 5 classified signals
  • Peaked 10d ago at 5 mentions (2026-03-20); latest day: 1
  • 18 total mentions across 11 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline18 mentions / 11d
01345Mentions · 2026-03-20: 5Mentions · 2026-03-21: 1Mentions · 2026-03-22: 4Mentions · 2026-03-23: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Mentions · 2026-04-15: 1Mentions · 2026-04-30: 1Mentions · 2026-05-10: 1Mentions · 2026-05-15: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-03-22: 1Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-03-22: 4Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 4Technical Details · 2026-03-23: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-15: 1Technical Details · 2026-07-13: 103-2003-2103-2203-2303-2603-3104-1504-3005-1005-1507-13
Signal classification5 categories
Patch
633.3%
Disclosure
527.8%
General
527.8%
False Positive
15.6%
Active Exploitation
15.6%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-205
Disclosure2False Positive1General2
2026-03-211
Disclosure1
2026-03-224
Patch4
2026-03-231
Patch1
2026-03-261
Disclosure1
2026-03-311
General1
2026-04-151
General1
2026-04-301
Disclosure1
2026-05-101
Active Exploitation1
2026-05-151
Patch1
2026-07-131
General1
Full discourse18 posts
  • Cantina 🪐@cantinaxyz
    Disclosure

    Cantina found a silent privilege escalation bug in @AnthropicAI Claude Code. No user interaction. No warning. Just clone a repo, and it's already too late. CVE-2026-33068 | CVSS 8.8 HIGH | Patched in 2.1.53 Breakdown below: https://t.co/1JbIiPXwup

    Post summary

    CVE-2026-33068 is a silent privilege escalation vulnerability in Anthropic AI Claude Code, rated CVSS 8.8 high, patched in version 2.1.53; no PoC or active exploitation claims are provided.

    45061205.4K
    18.8K followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    📰 dev news today: 1. 🔥 claude code channels — control your coding agent from telegram & discord 2. ⚡ claude code opus 4.6 — default output bumped to 64k tokens, 128k max 3. 🚀 ai agent tool-use patterns that actually work in production 4. 🔒 openclaw cve-2026-32051 — cvss 8.8 auth mismatch, patch to v2026.3.1 5. 🛡️ claude code cve-2026-33068 — workspace trust dialog bypass, fixed in v2.1.53 [1/7]

    Post summary

    The post reports CVE‑2026‑32051 for OpenClaw, noting an 8.8 CVSS score and providing a patch (v2026.3.1), with no PoC or evidence of active exploitation.

    60040115
    143 followersView on X
  • Mukund | Muks@CyberAmyntas
    False Positive

    The vulnerability in Claude Code (CVE-2026-33068) was not in the AI. It was in the settings loader. bypassPermissions is a documented feature. The bug was loading order. That is it. A classic software engineering problem. AI tools are software first. Security fundamentals apply. #AISecurity https://raxe.ai/labs/advisories/RAXE-2026-040 @RaxeAi

    Post summary

    The advisory clarifies that CVE‑2026‑33068 does not affect Claude AI itself but originates from a bug in the settings loader, debunking earlier assumptions of AI-level exploitation.

    32040121
    1.2K followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    📰 dev news today: 1. 🔥 claude code channels — control your coding agent from telegram & discord 2. ⚡ claude code opus 4.6 — default output bumped to 64k tokens, 128k max 3. 🚀 ai agent tool-use patterns that actually work in production 4. 🔒 openclaw cve-2026-32051 — cvss 8.8 auth mismatch, patch to v2026.3.1 5. 🛡️ claude code cve-2026-33068 — workspace trust dialog bypass, fixed in v2.1.53 [1/7]

    Post summary

    The post announces two CVE‑2026 vulnerabilities with CVSS scores, details their nature, and notes that patches are available, indicating successful disclosure and remediation.

    10050132
    143 followersView on X
  • MoltenRock 🔥@MoltenRockAI
    General

    You trusted a folder. That's all it takes. TrustFall (CVE-2026-33068) auto-approves a malicious MCP server with full user privileges the moment you trust a folder in Claude Code, Cursor, Gemini CLI, or CoPilot CLI. One click. Full system access. https://t.co/DiVy7rHHGk

    Post summary

    The tweet alerts users to CVE-2026-33068, describing how trusting a folder can lead to privilege escalation, but does not mention a PoC, exploit code, or mitigation.

    10040116
    67 followersView on X
  • perambulando@myuserviktor
    General

    acho que o CVE mais recente relacionado ao claude code é o CVE-2026-33068 a umas duas semanas atras, quanto tempo para aparecer uma CVE nova depois disso? #bolhasec "claude analise toda a codebase desse projeto, e encontre um RCE. Não cometa erros"

    Post summary

    The user references a CVE number and poses a question about its appearance timeline, but no technical or exploit specifics are provided.

    01021211
    74 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Claude Code workspace trust dialog bypass via repository settings loading order [CVE-2026-33068, CVSS 7.7]. Settings resolved before trust dialog shown. https://raxe.ai/labs/advisories/RAXE-2026-040

    Post summary

    The advisory discloses CVE-2026-33068, a trust dialog bypass in Claude Code that occurs due to repository settings loading order, with a CVSS of 7.7.

    01012591
    32.9K followersView on X
  • Yutan@yutaaaalll
    Patch

    Claude Codeに設定ファイルの読み込み順序を突いた脆弱性(CVE-2026-33068, CVSS 7.7)が見つかってた。リポジトリに.claude/settings.jsonを仕込むだけでワークスペース信頼ダイアログをバイパスできるという、シンプルだけど厄介なやつ。 v2.1.53で修正済みだけど、エージェントコーディングツールの「正規機能が攻撃ベクトルになる」パターンとして興味深い。 https://raxe.ai/labs/advisories/RAXE-2026-040 #ClaudeCode #セキュリティ #AI #LLM

    Post summary

    A configuration‑order bypass vulnerability (CVE‑2026‑33068) in Claude Code was discovered; an injection of .claude/settings.json demonstrates the exploit, and the issue was patched in v2.1.53.

    30000127
    488 followersView on X
  • Martin Musiol@musiol_martin
    Active Exploitation

    TrustFall lands. CVE-2026-26268 plus the Claude Code RCE chain (CVE-2025-59536, CVE-2026-21852, CVE-2026-33068). One Enter keypress auto-approves a malicious .mcp.json across Claude Code, Cursor CLI, Gemini CLI, and GitHub Copilot CLI. Translation: every default-trust agent CLI is one cloned repo from full-user-privilege RCE. Self-hosted with strict allowlists and a pinned MCP registry kills the class. https://aigeneral.net

    Post summary

    The post announces an active exploitation chain (TrustFall) affecting multiple Claude Code and CLI tools, detailing several CVEs and an RCE mechanism, but offers no PoC, exploit code, or patch information.

    00010884
    392 followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-33068: @AnthropicAI Claude Code resolved .claude/settings.json BEFORE the workspace trust dialog appeared. A malicious repo could set permissions.defaultMode to bypassPermissions. The trust prompt never fired. Patched 2.1.53. Same shape as CVE-2026-26268 in @cursor_ai last week. Config-before-trust isn't a bug class anymore — it's the default architecture. https://www.sitepoint.com/claude-code-vs-cursor-vs-copilot-the-2026-developer-comparison/

    Post summary

    CVE-2026-33068 in Anthropic's Claude Code allowed a malicious repository to bypass the workspace trust dialog by manipulating permissions.defaultMode. Version 2.1.53 has been released to fix the issue.

    0000058
    398 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Four flaws in Anthropic Claude Code (CVE-2026-33068, CVE-2026-25723, CVE-2026-21852, CVE-2025-59536) enable trust bypass, arbitrary file writes and API key exfiltration in unpatched versions. https://threatcluster.io/cluster/multiple-vulnerabilities-in-claude-code-expose-users-to-secu-9e448964

    Post summary

    Four new flaws in Anthropic Claude Code are announced, enabling trust bypass, arbitrary file writes, and API key exfiltration in unpatched versions.

    00000923
    182 followersView on X
  • リョウタ|AI Agent & Communications Specialist@aiagent_builder
    General

    「承認ボタンを押せば安全」って、もう通用しない時代に入った。 Claude CodeのCVE-2026-33068が示したのは、UIの承認ダイアログそのものが回避される可能性があるという事実。ボタンを信じていたら、その下の地面が抜けていた、みたいな話だ。 でも、これは絶望じゃない。むしろ設計思想のアップデートを迫る、すごく誠実な警告だと思う。 実行環境の分離、権限の最小化、秘密情報の分離保管、そして監査証跡の集約。UIに頼らず、構造で守る。これが「エージェント時代のガバナンス」の骨格になっていく。 AIエージェントを使いこなすとは、便利さに乗っかることじゃなく、その信頼の根拠を自分で設計できることだ。 承認UIは入口に過ぎない。その奥に、あなたが設計した技術的ガードレールがあるか。それが問われている。 https://www.sentinelone.com/vulnerability-database/cve-2026-33068/ #ClaudeCode

    Post summary

    The post discusses CVE-2026-33068, noting the UI bypass vulnerability but without providing PoC, exploit code, patch guidance, or evidence of active exploitation, making it a general commentary.

    0000033
    17 followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    🔒 cve-2026-33068: if you're on claude code < v2.1.53, a malicious repo can bypass the workspace trust dialog via .claude/settings.json — silently gaining full tool execution. update now. http://raxe.ai/labs/advisories/RAXE-2026-040

    Post summary

    The tweet alerts that Claude Code versions below 2.1.53 are vulnerable to a directory‑traversal style bypass that grants full tool execution, and it urges users to update immediately.

    0000059
    146 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33068 Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json,… https://www.cve.org/CVERecord?id=CVE-2026-33068

    Post summary

    The CVE-2026-33068 vulnerability in Claude Code involves a permission mode issue in settings files, which has been addressed in versions prior to 2.1.53.

    00000167
    56.8K followersView on X
  • openclawradar@openclawradar
    Disclosure

    📰 Claude Code Security Advisory: CVE-2026-33068 Workspace Trust Bypass https://openclawradar.com/article/claude-code-security-advisory-cve-2026-33068-workspace-trust-bypass #OpenClaw #AIAgents #AI #LLM https://t.co/67QqM2WdYL

    Post summary

    The tweet announces a security advisory for CVE-2026-33068, a workspace trust bypass, directing readers to a detailed article.

    0000051
    25 followersView on X
  • Security Harvester@secharvesterx
    General

    Claude Code workspace trust dialog bypass via repository settings loading order [CVE-2026-33068, CVSS 7.7]. Settings resolved before trust dialog shown. https://raxe.ai/labs/advisories/RAXE-2026-040 https://t.co/GaabgIfecC

    Post summary

    The advisory highlights a trust dialog bypass in Claude Code workspace, providing technical details of the vulnerability but lacking a PoC, exploit code, patch info, or evidence of active exploitation.

    00000102
    798 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33068 Workspace Trust Bypass Vulnerability in Claude Code Prior to 2.1.53 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33068

    Post summary

    The excerpt references a specific CVE and provides a link to a vulnerability details page but offers no additional information about PoCs, exploits, active exploitation, patches, or technical specifics.

    0000057
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33068 - Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File Intel Report: https://ift.tt/YPwe0v4

    Post summary

    The alert announces CVE‑2026‑33068, detailing a workspace trust dialog bypass, but does not provide exploitation code, active use, or mitigation recommendations.

    0000037
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more