A high-severity vulnerability affecting @anthropic-ai/claude-code versions >= 2.1.38, < 2.1.163, identified as CVE-2026-55607 with a CVSS score of 7.7, exists in the worktree handling component of Claude Code. This flaw allows an attacker to create worktrees named '.git' and navigate to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker can overwrite files in the user's home directory, such as.zshenv, ultimately leading to code execution outside of seatbelt sandbox restrictions. The vulnerability is exploitable by cloning a malicious repository containing prompt injection content and running Claude Code against it. This attack vector has a high business impact due to its potential to result in unsandboxed code execution, potentially allowing attackers to access sensitive data or execute malicious code with elevated privileges.
We recommend you to update claude-code to version 2.1.163.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting @anthropic-ai/claude-code versions >= 2.1.38, < 2.1.163, identified as CVE-2026-55607 with a CVSS score of 7.7, exists in the worktree handling component of Claude Code. This flaw allows an attacker to create worktrees named '.git' and navigate to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker can overwrite files in the user's home directory, such as.zshenv, ultimately leading to code execution outside of seatbelt sandbox restrictions. The vulnerability is exploitable by cloning a malicious repository containing prompt injection content and running Claude Code against it. This attack vector has a high business impact due to its potential to result in unsandboxed code execution, potentially allowing attackers to access sensitive data or execute malicious code with elevated privileges.
We recommend you to update claude-code to version 2.1.163.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]