CVE-2026-40068
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security-advisories@github.com — https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | @anthropic-ai/claude-code | >=2.1.63,<2.1.84 | 2.1.84 |
| NPM | @anthropic-ai/claude-code | >= 2.1.63, < 2.1.84 | 2.1.84 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| anthropic | claude_code | {"startIncluding":"2.1.63","endExcluding":"2.1.84"} | 2.1.84 |
References
CWEs
CWE-20 CWE-77
Verify integrity in audit chain (admin only). AS-IS.