CVE-2026-40068Disclosure(anthropic / claude_code)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run Claude Code within it, and the attacker must know or guess a path the victim had already trusted. This issue has been fixed in version 2.1.84.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 8 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-30); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-27: 1Mentions · 2026-04-30: 2Mentions · 2026-05-03: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 104-2404-2704-3005-0305-0505-06
Signal classification1 categories
Disclosure
8100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-271
Disclosure1
2026-04-302
Disclosure2
2026-05-031
Disclosure1
2026-05-052
Disclosure2
2026-05-061
Disclosure1
Full discourse8 posts
  • 株式会社エーアイセキュリティラボ@aeyeseclab
    Disclosure

    【脆弱性発見のお知らせ】 弊社取締役副社長 安西真人が Anthropic社のAIコーディングエージェント「Claude Code」における 重大な脆弱性を発見(CVE-2026-40068)しました。 ▼詳細はこちら https://na2.hubs.ly/H056h0g0 https://t.co/8p8frc7v3Z

    Post summary

    A corporate announcement highlights the discovery of a critical vulnerability (CVE‑2026‑40068) in Anthropic’s Claude Code, with additional information available via linked resources.

    02022380
    120 followersView on X
  • ぽねっと@ponet2017
    Disclosure

    先月にCodexのゼロディ脆弱性[識別子は ZDI-26-305、CVSS 深刻度スコアは 8.6(High)]が発表やClaude Codeで重大な脆弱性(CVE-2026-40068)が発見されました。 前者はZDI が報告してから2か月、OpenAI は再現を確認したものの、「自社のバグ報奨金プログラムの対象外」「Codex のデフォルトの公開範囲に含まれていない」 として修正を見送り。ZDI はやむなく 未パッチのまま公表するという経緯があり、ユーザーを落胆させる事案がありました。

    Post summary

    The text announces the discovery of a high‑severity zero‑day in Codex (ZDI‑26‑305) and a critical CVE in Claude Code (CVE‑2026‑40068), noting that OpenAI confirmed but declined to patch the issue, leaving it unaddressed.

    1001039
    3.1K followersView on X
  • ぽねっと@ponet2017
    Disclosure

    Codexはサンドボックス迂回のゼロデイ脆弱性、Claude Codeは重大な脆弱性(CVE-2026-40068)が発見されたという。 Gemini CLIやGithub Copilot CLIは大丈夫なのか? しかしこの問題はOpenAIに報告され再現性を確認したにも関わらず、自社のバグ報奨金プログラムの対象外であるとして、OpenAIはこの脆弱性を却下。当該脆弱性は「Codex」製品のデフォルトの公開範囲に含まれていないとし、修正を見送ったとのこと。 何という対応だ。

    Post summary

    The post announces a newly discovered zero‑day vulnerability (CVE‑2026‑40068) in Codex, noting that OpenAI has rejected remediation, but provides no PoC, exploit code, or patch details.

    0001083
    3.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40068 Arbitrary Hook Execution in Claude Code via Malicious Git Worktree Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40068

    Post summary

    The post discloses CVE‑2026‑40068 as an arbitrary hook execution vulnerability in Claude code via malicious Git worktree configuration, without providing PoC, exploit, patch, or evidence of active exploitation.

    0000066
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40068 In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attack… https://www.cve.org/CVERecord?id=CVE-2026-40068 ----- Traducción: CVE-2026-40068 En … http://infoflow.cloud`

    Post summary

    The post summarizes CVE-2026-40068, noting a flaw in Claude Code’s folder trust logic that fails to validate git worktree commondir contents, and points to the CVE record, but provides no PoC, exploit, or patch information.

    0000040
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40068 In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attack… https://www.cve.org/CVERecord?id=CVE-2026-40068

    Post summary

    A new vulnerability, CVE‑2026‑40068, is disclosed affecting Claude Code 2.1.63‑2.1.83; the flaw stems from unvalidated git worktree commondir handling, but no PoC, exploit code, or active exploitation has been reported.

    00000218
    57.4K followersView on X
  • 一石 凛@V7YZZmZTnO32BV0
    Disclosure

    AI コーディングエージェント「Claude Code」に重大な脆弱性 『エーアイセキュリティラボは4月27日、同社の取締役副社長である安西真人氏が、米国Anthropic社のAIコーディングエージェント「Claude Code」における重大な脆弱性(CVE-2026-40068)を発見したと発表』 https://news.yahoo.co.jp/articles/0af2fd75e69a8b8263d8a4c6421df05ef52ea9cc

    Post summary

    The notice announces the discovery of a new critical vulnerability, CVE-2026-40068, in Anthropic's Claude Code AI coding agent, with no further technical or mitigation details provided.

    00000121
    196 followersView on X
  • Masato Anzai@masato_anzai
    Disclosure

    I recently reported a vulnerability in @AnthropicAI 's Claude Code, and it has officially been assigned CVE-2026-40068. Huge thanks to their security team and HackerOne for their swift response and smooth coordination throughout the disclosure process! https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77

    Post summary

    The user reports that a vulnerability in Anthropic AI’s Claude Code has been disclosed and assigned CVE-2026-40068; the tweet confirms disclosure but contains no PoC, exploit details, active exploitation, patch, or technical specifics.

    00000169
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more