GHSA-q5hj-mxqh-vv77
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
Quick fix
GHSA-q5hj-mxqh-vv77 — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.
npm install @anthropic-ai/claude-code@2.1.84Details
Claude Code used the git worktree `commondir` file when determining folder trust but did not validate its contents. By crafting a repository with a `commondir` file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in `.claude/settings.json`. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Claude Code thanks [hackerone.com/masato_anzai](https://hackerone.com/masato_anzai) for reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.1.63Fixed in: 2.1.84npm install @anthropic-ai/claude-code@2.1.84