VDB
Sign up
HIGH

GHSA-q5hj-mxqh-vv77

Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution

Quick fix

GHSA-q5hj-mxqh-vv77 — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.

npm install @anthropic-ai/claude-code@2.1.84

Details

Claude Code used the git worktree `commondir` file when determining folder trust but did not validate its contents. By crafting a repository with a `commondir` file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks defined in `.claude/settings.json`. Exploiting this required the victim to clone a malicious repository and run Claude Code within it, and for the attacker to know or guess a path the victim had already trusted.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Claude Code thanks [hackerone.com/masato_anzai](https://hackerone.com/masato_anzai) for reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@anthropic-ai/claude-code
Introduced in: 2.1.63Fixed in: 2.1.84
Fixnpm install @anthropic-ai/claude-code@2.1.84

References