CVE-2026-33068 is a high-severity vulnerability affecting Anthropic Claude Code versions prior to 2.1.53, allowing a workspace trust dialog bypass. A malicious repository could silently enable a permissive mode by pre-configuring settings, leading to tool execution without explicit user consent. With a CVSS score of 8.8 (High), this network-exploitable flaw has low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code exists and it is not listed in CISA KEV, it is on the Hot List and receiving significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.53CPE matchmatch criteria | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Mar 19, 2026Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Mar 19, 2026Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
Mar 19, 2026