A critical sandbox escape vulnerability (CVE-2026-55607) has been discovered in Anthropic's Claude Code, allowing malicious repositories to execute arbitrary code on a user's system. The vulnerability, reported by security researcher metnew, exploits a combination of Git's worktree handling and symlink manipulation to overwrite shell initialization files. Anthropic has rated the vulnerability as High and has released a fix in version 2.1.163, which is automatically applied to users on the standard update channel. AI
IMPACT This vulnerability highlights the risks of AI coding assistants interacting with complex systems like Git, potentially leading to wider security concerns for developers.
RANK_REASON Disclosure of a security vulnerability in a specific AI coding tool.
Read on dev.to — Claude Code tag →
- Anthropic
- Claude Code
- CVE-2026-55607
- CVSS v4.0
- GHSA-7835-87q9-rgvv
- Git
- GitHub Copilot CLI
- Hackerone
- metnew
- ~/.zshenv
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →