漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Vulnerability Description
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A malicious repository could set permissions.defaultMode to bypassPermissions in its committed .claude/settings.json, causing the trust dialog to be silently skipped on first open. This allowed a user to be placed into a permissive mode without seeing the trust confirmation prompt, making it easier for an attacker-controlled repository to gain tool execution without explicit user consent. This issue has been patched in version 2.1.53.
CVSS Information
N/A
Vulnerability Type
在安全决策中依赖未经信任的输入
Vulnerability Title
Claude Code 安全漏洞
Vulnerability Description
Claude Code是Anthropic开源的一个终端原生AI编程工具。 Claude Code 2.1.53之前版本存在安全漏洞,该漏洞源于权限模式解析顺序不当,可能导致绕过工作区信任确认对话框。
CVSS Information
N/A
Vulnerability Type
N/A