Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-55607— Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Quick assessment

Affected
anthropics claude-code
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

anthropics claude-code是anthropics的AI辅助编程工具。 Anthropic Claude Code 2.1.38版本至2.1.163之前版本存在安全漏洞,该漏洞源于工作树处理允许创建名为“.git”的工作树并导航到沙箱环境之外的工作树,导致git目录混淆攻击,通过利用符号链接操作和git fsmonitor执行,攻击者可以覆盖用户主目录中的文件,导致在seatbelt沙箱限制之外执行代码。

AI Predicted 7.8 Difficulty: Easy EPSS 0.69% · P51

Affected Version Matrix 1

VendorProduct Version RangeStatus
anthropics claude-code >= 2.1.38, < 2.1.163 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55607

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it. This vulnerability is fixed in 2.1.163.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
Anthropic Claude Code 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
anthropics claude-code是anthropics的AI辅助编程工具。 Anthropic Claude Code 2.1.38版本至2.1.163之前版本存在安全漏洞,该漏洞源于工作树处理允许创建名为“.git”的工作树并导航到沙箱环境之外的工作树,导致git目录混淆攻击,通过利用符号链接操作和git fsmonitor执行,攻击者可以覆盖用户主目录中的文件,导致在seatbelt沙箱限制之外执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
anthropics claude-code >= 2.1.38, < 2.1.163 -

II. Public POCs for CVE-2026-55607

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55607

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-55607 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55607

No comments yet


Leave a comment