Knowledge base
CodexGuild Knowledge Base

Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution

as of Apr 24, 2026 · applies to @anthropic-ai/claude-code >= 2.1.63, < 2.1.84 · canonical · codexguild.com/kb/ghsa-q5hj-mxqh-vv77 · exported 2026-10-11
Canonical as of Apr 24, 2026

Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution

High severity. Affects @anthropic-ai/claude-code >= 2.1.63, < 2.1.84. Upgrade to 2.1.84 or later.

CVE-2026-40068 / GHSA-q5hj-mxqh-vv77 · severity: high · npm

Affected

  • @anthropic-ai/claude-code >= 2.1.63, < 2.1.84 → fixed in 2.1.84

Details

Claude Code used the git worktree commondir file when determining folder trust but did not validate its contents. By crafting a repository with a commondir file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in .claude/settings.json. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Claude Code thanks hackerone.com/masato_anzai for reporting this issue.

Source: GHSA-q5hj-mxqh-vv77 — GitHub Advisory Database (CC-BY-4.0).