Reliance on Untrusted Inputs in a Security Decision in Claude Code - CVE-2026-33068
Published: April 30, 2026
Claude Code
Anthropic
Description
The vulnerability allows a remote attacker to gain tool execution without explicit user consent.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the workspace trust dialog logic when processing the repo-controlled .claude/settings.json file on first open. A remote attacker can commit a malicious settings file that sets permissions.defaultMode to bypassPermissions to gain tool execution without explicit user consent.
User interaction is required when the victim first opens a malicious repository.