by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
6 packages
- claude-code-acp
- claude-code-router
- gnomeExtensions.claude-code-usage
- gnomeExtensions.claude-code-switcher
- vscode-extensions.anthropic.claude-code
- gnomeExtensions.claude-code-usage-indicator
- @LeSuisse accepted
- @LeSuisse published on GitHub
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run Claude Code within it, and the attacker must know or guess a path the victim had already trusted. This issue has been fixed in version 2.1.84.
References
Affected products
- ==>= 2.1.63, < 2.1.84
Matching in nixpkgs
pkgs.claude-code
Agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster
pkgs.claude-code-bin
Agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster
Ignored packages (6)
pkgs.claude-code-acp
None
pkgs.claude-code-router
Tool to route Claude Code requests to different models and customize any request
pkgs.gnomeExtensions.claude-code-usage
Display Claude Code usage in the top panel. This extension uses anthropic.com services. This extension is not affiliated, funded, or in any way associated with Claude.
pkgs.gnomeExtensions.claude-code-switcher
A GNOME shell extension for quickly switching Claude Code API providers with enhanced performance and reliability.
pkgs.vscode-extensions.anthropic.claude-code
Harness the power of Claude Code without leaving your IDE
pkgs.gnomeExtensions.claude-code-usage-indicator
Shows remaining time and usage percentage for Claude Code sessions in the top panel. Displays format like '3h 12m (30%)' showing both time remaining and percentage consumed. Automatically refreshes every 5 minutes.
Package maintainers
-
@xiaoxiangmoe ZHAO JinXiang <xiaoxiangmoe@gmail.com>
-
@omarjatoi Omar Jatoi
-
@adeci Alex Decious <alex.decious@gmail.com>
-
@oskarwires Oskar <me@usbcable.io>
-
@mirkolenz Mirko Lenz <mirko@mirkolenz.com>
-
@malob Malo Bourgon <mbourgon@gmail.com>
-
@markus1189 Markus Hauck <markus1189@gmail.com>