OSV 1.4.0 · github-reviewed · 修改于 2026-05-08 23:31
发布时间
2026-04-25 00:34
GitHub 审查时间
2026-04-25 00:34
NVD 发布时间
2026-05-06 05:16
源文件
advisories/github-reviewed/2026/04/GHSA-q5hj-mxqh-vv77/GHSA-q5hj-mxqh-vv77.json
Claude Code used the git worktree commondir file when determining folder trust but did not validate its contents. By crafting a repository with a commondir file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in .claude/settings.json. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Claude Code thanks hackerone.com/masato_anzai for reporting this issue.