Security Vulnerability in Claude Code by Anthropics
CVE-2026-40068

7.7HIGH

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
5 May 2026

What is CVE-2026-40068?

In specific versions of Claude Code, an input validation flaw allows an attacker to exploit the folder trust determination logic. By crafting a malicious repository containing a commondir file that elements the victim previously trusted, the vulnerable system could unwittingly execute potentially harmful scripts defined in the associated configuration file. This exploitation necessitates that the victim clones the crafted repository and runs Claude Code within it. Victims must also have an understanding of which trusted paths to exploit. This significant vulnerability underscores the importance of validating content from external repositories.

Affected Version(s)

claude-code >= 2.1.63, < 2.1.84

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.