Md Ismail Šojal 🕷️[verified]@0x0SojalSecExploit
CVE‑2026‑55607 enables unsandboxed RCE in Claude Code through .git worktree manipulation; Anthropic offered a $3,700 bounty and recommends patching to v2.1.163.
Md Ismail Šojal 🕷️[verified]@0x0SojalSecDisclosure
The text announces CVE‑2026‑55607, a high‑severity sandbox escape, and provides links to a GitHub advisory and a write‑up, but offers no exploitation code, patch details, or evidence of active abuse.
Tochukwu Okonkwor[verified]@tokonkworDisclosure
The text announces two new CVEs, CVE-2026-71963 and CVE-2026-55607, affecting several AI agents in a formal disclosure.
クロニキ|Claude Code専門家[verified]@chroniki_aiDisclosure
The post describes the technical details of CVE-2026‑55607, noting that a prompt‑injection in Claude Code can create a malicious .git worktree, leading to sandbox escape and unauthorized system file access.
Prasenjit Sarkar[verified]@stretchcloudExploit
The tweet explains a sandbox escape via worktree path confusion with detailed exploitation steps, notes an auto‑update fix, and highlights that no active attacks are reported.
Bryan[verified]@so_sthbryanPoC
The post announces CVE‑2026‑55607, provides a link to a GitHub PoC, includes technical details of the sandbox escape, and urges users to patch to mitigate the risk.
metnew@v_metnewPoC
The tweet references CVE‑2026‑55607, linking to a write‑up that includes a proof of concept for a sandbox escape via prompt injection, but it does not report a public exploit, patch, or active exploitation.
N45HT@N45HTOfficialPoC
A write‑up for CVE‑2026‑55607 outlines unsandboxed code execution via .git worktree confusion, includes a PoC and vendor advisory, and is supported by a $3,700 Anthropic bug bounty.