{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/claude-code--2.1.38--2.1.163/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-55607"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Claude Code (\u003e= 2.1.38, \u003c 2.1.163)"],"_cs_severities":["high"],"_cs_tags":["sandbox-escape","code-execution","git","path-confusion","symlink"],"_cs_type":"advisory","_cs_vendors":["Anthropic"],"content_html":"\u003cp\u003eA high-severity sandbox escape vulnerability, identified as CVE-2026-55607, has been discovered in Claude Code, specifically impacting versions 2.1.38 through 2.1.162 of the \u003ccode\u003e@anthropic-ai/claude-code\u003c/code\u003e npm package. This flaw stems from Claude Code's insecure handling of Git worktrees, which permits the creation of \u003ccode\u003e\u0026quot;.git\u0026quot;\u003c/code\u003e named worktrees and navigation outside the intended sandbox context, facilitating Git directory confusion attacks. By leveraging symlink manipulation and abusing Git's \u003ccode\u003efsmonitor\u003c/code\u003e execution capabilities during worktree operations, an attacker can overwrite critical configuration files in a user's home directory, such as \u003ccode\u003e.zshenv\u003c/code\u003e. Successful exploitation necessitates user interaction, specifically the cloning of a malicious repository containing prompt injection content and then executing Claude Code against this repository. This can lead to arbitrary code execution outside of the application's security sandbox, posing a significant risk for data compromise and system control. The vulnerability was reported by hackerone.com/metnew and has since been patched.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a specialized malicious Git repository containing specific worktree configurations and prompt injection content.\u003c/li\u003e\n\u003cli\u003eThe malicious repository is designed to exploit the worktree handling vulnerability within Claude Code.\u003c/li\u003e\n\u003cli\u003eA victim is induced, likely through social engineering or other means, to clone this malicious repository onto their system.\u003c/li\u003e\n\u003cli\u003eThe victim then runs the vulnerable Claude Code application (version \u0026gt;= 2.1.38, \u0026lt; 2.1.163) against the cloned malicious repository.\u003c/li\u003e\n\u003cli\u003eDuring Claude Code's internal Git worktree operations, the attacker's crafted repository leverages symlink manipulation and triggers Git's \u003ccode\u003efsmonitor\u003c/code\u003e execution feature.\u003c/li\u003e\n\u003cli\u003eThis sequence of actions exploits the \u0026quot;Git directory confusion\u0026quot; vulnerability, allowing the creation of a \u003ccode\u003e\u0026quot;.git\u0026quot;\u003c/code\u003e named worktree outside the application's sandbox.\u003c/li\u003e\n\u003cli\u003eThe attacker then overwrites sensitive user configuration files, such as \u003ccode\u003e.zshenv\u003c/code\u003e or other shell initialization files, located in the victim's home directory.\u003c/li\u003e\n\u003cli\u003eUpon a subsequent login or shell invocation by the victim, the maliciously modified configuration file executes arbitrary code with the user's privileges, effectively achieving unsandboxed code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-55607 leads to a complete sandbox escape, allowing an attacker to execute arbitrary code outside the confines of the Claude Code application's security restrictions. This can result in compromise of the user's system, including data exfiltration, installation of further malware, or disruption of system operations. The vulnerability targets user-specific configuration files in the home directory, meaning an attacker could gain persistent access or elevate privileges within the user's session. While specific victim counts are not provided, any user running affected versions of Claude Code and interacting with a malicious Git repository is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update \u003ccode\u003enpm/@anthropic-ai/claude-code\u003c/code\u003e to version 2.1.163 or later to patch CVE-2026-55607.\u003c/li\u003e\n\u003cli\u003eEducate users about the risks of cloning untrusted Git repositories and running applications like Claude Code against them.\u003c/li\u003e\n\u003cli\u003eMonitor file system events for unusual modifications to shell configuration files (e.g., \u003ccode\u003e.zshenv\u003c/code\u003e, \u003ccode\u003e.bashrc\u003c/code\u003e, \u003ccode\u003e.profile\u003c/code\u003e) in user home directories, particularly after Git operations or application launches.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T16:58:16Z","date_published":"2026-07-24T16:58:16Z","id":"https://feed.craftedsignal.io/briefs/2026-07-claude-code-sandbox-escape/","summary":"A high-severity sandbox escape vulnerability, CVE-2026-55607, exists in Claude Code's worktree handling, allowing attackers to achieve unsandboxed code execution by manipulating symlinks and exploiting Git fsmonitor during worktree operations to overwrite user home directory files like .zshenv, requiring a user to clone a malicious repository and run Claude Code against it.","title":"Claude Code Sandbox Escape via Git Worktree Path Confusion (CVE-2026-55607)","url":"https://feed.craftedsignal.io/briefs/2026-07-claude-code-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Claude Code (\u003e= 2.1.38, \u003c 2.1.163)","version":"https://jsonfeed.org/version/1.1"}