Claude Code's Git Worktree Handling Let a Malicious Repo Escape the Sandbox (CVE-2026-55607)
This story is from 2026-09-14. It is preserved in the archive; the latest stories are on the live feed.
Cloning a repository and running Claude Code against it was enough. No prompt approval, no explicit command — just opening the project. What the source says Anthropic's own GitHub Security Advisory ( GHSA-7835-87q9-rgvv , CVE-2026-55607) documents a sandbox-escape chain in Claude Code versions ≥2.1…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-14 09:53 · DEV Community — AI
Claude Code's Git Worktree Handling Let a Malicious Repo Escape the Sandbox (CVE-2026-55607)