Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes—the security story is real, but “just open a malicious project” is shorthand. The documented attacks generally required launching Claude Code in, or directing it at, an untrusted repository. Check Point Research and NVD records describe flaws that let repository-controlled settings run shell commands, redirect API traffic, weaken permission checks, or bypass trust decisions in specific Claude Code versions. Downloading a repository alone did not automatically compromise every computer.

Why a project can control more than source code

Ordinary source files are usually passive until a developer compiles or runs them. An agentic coding tool adds another category: project-local instructions and configuration that can influence hooks, tools, permissions, environment variables, network destinations and MCP integrations.

Claude Code supports project settings in files such as .claude/settings.json. Check Point Research reported that repository-controlled settings could define hooks and other behavior. That makes a dotfile part of the execution surface, even though it looks like data rather than a program. The broader supply-chain lesson is that documentation, Git metadata and agent configuration deserve the same suspicion as build scripts and package-install hooks. Check Point’s technical analysis

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Claude Code’s trust prompt was meant to protect

  1. The user starts Claude Code in a directory or points it at a repository.
  2. The client determines whether that directory is trusted.
  3. A trust prompt asks the user to approve project-local behavior.
  4. Configuration, hooks and other potentially dangerous actions should be subject to that decision.

Anthropic’s postmortem describes the affected class as activity occurring before the trust dialog. In the disclosed bugs, project-controlled input could be parsed or acted on before meaningful consent had been established. The issue was therefore not simply that Claude might follow hostile text in a README; some startup paths connected repository data to commands or network behavior first. Anthropic’s explanation of the trust-boundary failures

The two findings that started the warning

CVE-2025-59536: commands before trust

Check Point Research reported that a malicious project could place a hook in .claude/settings.json. Starting Claude Code in that project could execute the hook before the trust decision was properly enforced, potentially allowing arbitrary shell commands or a reverse shell. This is materially different from a prompt-injection attempt that merely asks the model to do something.

Versions before 1.0.111 were affected. Anthropic’s normal auto-update path was intended to distribute the fix; users on manual installations had to update themselves. The NVD record documents the affected range and remediation. NVD: CVE-2025-59536

CVE-2026-21852: API endpoint redirection

A separate flaw affected versions before 2.0.65. A repository could set ANTHROPIC_BASE_URL to an attacker-controlled endpoint. Claude Code could then send API requests there before trust confirmation, potentially exposing the Anthropic API key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The consequences depend on that key’s permissions and the services it can reach. A stolen credential could enable access to shared workspace data, changes or deletion, unwanted uploads, or unexpected API charges. Those are possible downstream effects, not proof that every account would suffer all of them. NVD: CVE-2026-21852

The trust-boundary problem continued in later releases

Updating only for the original 2025 report is not enough. Subsequent disclosures affected different versions and attack paths. Each entry below has its own prerequisites; no single row means every release was vulnerable to every technique.

Vulnerability Affected versions Fixed version Core issue
CVE-2025-59536 Before 1.0.111 1.0.111 Code execution before trust confirmation
CVE-2026-21852 Before 2.0.65 2.0.65 API endpoint redirection and possible key exposure
CVE-2026-33068 Before 2.1.53 2.1.53 Repository-controlled selection of bypassPermissions
CVE-2026-40068 2.1.63–2.1.83 2.1.84 Malicious Git worktree commondir causing trust confusion
CVE-2026-54316 0.2.54–2.1.162 2.1.163 Exfiltration through attacker-controlled WebFetch behavior
CVE-2026-55607 2.1.38–2.1.162 2.1.163 Symlink and Git fsmonitor behavior enabling file overwrite and code execution under specific conditions

See the individual NVD records for CVE-2026-33068, CVE-2026-40068, CVE-2026-54316 and CVE-2026-55607.

Is an updated Claude Code safe enough?

Install current updates through Claude Code’s normal mechanism. Anthropic documents the claude update command for manual updates and says the tool normally keeps itself updated. Confirm the installed version afterward, and check Anthropic’s security advisories before relying on any version as current because releases and fixes change. Anthropic support documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A patch closes known defects; it does not make an arbitrary repository trustworthy. Package lifecycle scripts, Git hooks, build tools, editor extensions and future undiscovered bugs remain relevant. Sandboxing also is not a complete answer if the client’s filesystem or Git integration has its own weakness.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A safer workflow for an unfamiliar repository

  1. Update before inspection. Do not use an old Claude Code installation to examine unknown code.
  2. Keep Claude Code out initially. Clone the repository without launching the agent in it.
  3. Review control files manually. Check .claude/settings.json, CLAUDE.md, MCP configuration, hooks, shell scripts, Git worktree metadata, package-manager lifecycle scripts, Docker files, Makefiles, task runners and CI configuration.
  4. Search for redirection and credential access. Look for ANTHROPIC_BASE_URL, proxy settings, curl or wget commands, and references to environment variables, tokens and credential stores.
  5. Use an ephemeral environment. Prefer a disposable VM or container with no personal SSH keys, cloud credentials, browser profile, password store or production token. Do not grant host sockets or privileged access merely because a container is being used.
  6. Use least privilege. If an API key is necessary, make it short-lived, narrowly scoped and subject to spending limits.
  7. Restrict networking. Keep initial inspection offline or behind controlled egress where practical.
  8. Review every permission prompt. Never enable a permissive mode such as bypassing permissions for an unknown project.
  9. Monitor activity. Watch API usage, workspace changes, uploads and billing for anomalies.
  10. Destroy the environment afterward. Deleting a disposable VM is safer than trying to clean a workstation that may have executed hostile code.

These controls reduce exposure; none guarantees safety.

If Claude Code already ran on a suspicious project

  1. Disconnect or isolate the machine from sensitive networks.
  2. Revoke and rotate Anthropic keys plus credentials in environment variables, shell profiles, SSH agents, cloud CLIs, package registries and local files.
  3. Inspect shell startup files, scheduled tasks, launch agents, Git hooks and recently modified files.
  4. Review Anthropic usage, workspace and billing activity, then check GitHub, cloud, registry and CI/CD logs.
  5. Preserve evidence before deleting the repository if investigation may be required.
  6. Rebuild the machine when there is evidence of arbitrary code execution and it held valuable credentials.
  7. Notify your security team or incident-response provider.

Rotating only the Anthropic key is insufficient if the vulnerable path may have achieved host-level execution.

What organizations should enforce

  • Centralized version enforcement and rapid patch deployment.
  • Approved project configuration and review of hooks and MCP servers.
  • Ephemeral developer environments with no standing production credentials.
  • Network egress controls that prevent unknown endpoints from receiving agent traffic.
  • Short-lived, least-privilege API keys with budget alerts and rapid revocation.
  • Audit logs covering agent launches, tool calls, file changes, network requests and credential use.
  • Repository and dependency scanning as a complementary layer, not a substitute for endpoint isolation.

Bottom line

The vulnerabilities were real, but the accurate lesson is narrower than the headline: launching Claude Code against an untrusted repository made initialization part of the security boundary. Update the client, inspect project-local instructions as hostile input, isolate the environment and keep credentials disposable. Do not treat a trust prompt—or a patched client—as proof that unknown code is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.