PulseAugur
实时 10:50:22
English(EN) Claude Code's Git Worktree Handling Let a Malicious Repo Escape the Sandbox (CVE-2026-55607)

Anthropic 的 Claude Code 易受 Git 沙箱逃逸漏洞影响 (CVE-2026-55607)

AnthropicClaude Code 中发现了一个关键的沙箱逃逸漏洞 (CVE-2026-55607),允许恶意仓库在用户系统上执行任意代码。该漏洞由安全研究员 metnew 报告,利用了 Git 的 worktree 处理和符号链接操作的组合来覆盖 shell 初始化文件。Anthropic 将该漏洞评为“高危”,并在 2.1.163 版本中发布了修复程序,该程序会自动应用于标准更新渠道的用户。 AI

影响 此漏洞凸显了 AI 编码助手与 Git 等复杂系统交互的风险,可能导致开发者面临更广泛的安全问题。

排序理由 披露了特定 AI 编码工具的安全漏洞。

在 dev.to — Claude Code tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Anthropic 的 Claude Code 易受 Git 沙箱逃逸漏洞影响 (CVE-2026-55607)

本文如何被排名

Signal score
50 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
披露了特定 AI 编码工具的安全漏洞。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Ramdai Bista ·

    Claude Code 的 Git Worktree 处理让恶意仓库逃离沙箱 (CVE-2026-55607)

    <p>Cloning a repository and running Claude Code against it was enough. No prompt approval, no explicit command — just opening the project.</p> <h2> What the source says </h2> <p>Anthropic's own GitHub Security Advisory (<a href="https://github.com/anthropics/claude-code/security/…