株式会社エーアイセキュリティラボ[verified]@aeyeseclabDisclosure
A corporate announcement highlights the discovery of a critical vulnerability (CVE‑2026‑40068) in Anthropic’s Claude Code, with additional information available via linked resources.
ぽねっと[verified]@ponet2017Disclosure
The text announces the discovery of a high‑severity zero‑day in Codex (ZDI‑26‑305) and a critical CVE in Claude Code (CVE‑2026‑40068), noting that OpenAI confirmed but declined to patch the issue, leaving it unaddressed.
ぽねっと[verified]@ponet2017Disclosure
The post announces a newly discovered zero‑day vulnerability (CVE‑2026‑40068) in Codex, noting that OpenAI has rejected remediation, but provides no PoC, exploit code, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post discloses CVE‑2026‑40068 as an arbitrary hook execution vulnerability in Claude code via malicious Git worktree configuration, without providing PoC, exploit, patch, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
The post summarizes CVE-2026-40068, noting a flaw in Claude Code’s folder trust logic that fails to validate git worktree commondir contents, and points to the CVE record, but provides no PoC, exploit, or patch information.
CVE@CVEnewDisclosure
A new vulnerability, CVE‑2026‑40068, is disclosed affecting Claude Code 2.1.63‑2.1.83; the flaw stems from unvalidated git worktree commondir handling, but no PoC, exploit code, or active exploitation has been reported.
一石 凛@V7YZZmZTnO32BV0Disclosure
The notice announces the discovery of a new critical vulnerability, CVE-2026-40068, in Anthropic's Claude Code AI coding agent, with no further technical or mitigation details provided.
Masato Anzai@masato_anzaiDisclosure
The user reports that a vulnerability in Anthropic AI’s Claude Code has been disclosed and assigned CVE-2026-40068; the tweet confirms disclosure but contains no PoC, exploit details, active exploitation, patch, or technical specifics.