Security: anthropics/claude-code
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionGHSA-7835-87q9-rgvv published
Jun 25, 2026 by ddworkenHigh -
Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchGHSA-fg94-h982-f3mm published
Jun 13, 2026 by ddworkenModerate -
Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File WriteGHSA-4vp2-6q8c-pvq2 published
Jun 25, 2026 by OctavianGuzuModerate -
Local Privilege Escalation via Directory Junction in CoworkVMServiceGHSA-5p5x-5294-qhp3 published
May 6, 2026 by OctavianGuzuHigh -
SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote SessionsGHSA-3rwf-2g6p-c2f9 published
May 6, 2026 by OctavianGuzuHigh -
Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on WindowsGHSA-5cwg-9f6j-9jvx published
Apr 17, 2026 by OctavianGuzuModerate -
Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code ExecutionGHSA-q5hj-mxqh-vv77 published
Apr 24, 2026 by OctavianGuzuHigh -
Workspace Trust Dialog Bypass via Repo-Controlled Settings FileGHSA-mmgp-wc2j-qcv7 published
Mar 18, 2026 by dmckennirey-antHigh -
Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside WorkspaceGHSA-vp62-r36r-9xqp published
Apr 20, 2026 by OctavianGuzuHigh -
Command Injection via Directory Change Bypasses Write ProtectionGHSA-66q4-vfjg-2qhh published
Feb 6, 2026 by ddworkenHigh