Claude Code Security Advisory: CVE-2026-33068 Workspace Trust Bypass

✍️ OpenClawRadar📅 Published: March 20, 2026🔗 Source
Claude Code Security Advisory: CVE-2026-33068 Workspace Trust Bypass
Ad

Security Vulnerability in Claude Code

A security advisory has been issued for Claude Code users regarding CVE-2026-33068, a vulnerability with CVSS score 7.7 (HIGH). The issue affects Claude Code versions prior to 2.1.53.

Technical Details

The vulnerability allows malicious repositories to bypass the workspace trust confirmation dialog. Claude Code includes a legitimate feature called bypassPermissions in .claude/settings.json that lets users pre-approve specific operations in trusted workspaces.

The bug was in the order of operations: settings from the repository's .claude/settings.json were loaded before the workspace trust dialog was shown to the user. This means a cloned repository could include a settings file that grants itself elevated permissions before the user has a chance to review it.

Important nuance: bypassPermissions is a documented, intentional feature. The vulnerability is not in the feature itself but in the loading sequence.

Ad

What Users Should Do

  • Run claude --version to confirm you are on 2.1.53 or later
  • Before opening any unfamiliar repository with Claude Code, check whether it contains a .claude/settings.json file and review its contents
  • If you have been working with repositories from untrusted sources on earlier versions, consider whether any unexpected operations were performed

Fix

Anthropic fixed this vulnerability in version 2.1.53 by reordering the loading sequence. The full advisory with technical details is available at https://raxe.ai/labs/advisories/RAXE-2026-040.

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

OpenClaw Skill Analyzer: Static Security Scanner for AI Agent Skills
Security

OpenClaw Skill Analyzer: Static Security Scanner for AI Agent Skills

A developer built a static analyzer that scans OpenClaw skills for security risks before installation, with 40+ detection rules across 12 categories including prompt injection and data exfiltration.

OpenClawRadar
Claude Code Security Plugin: Pushing AppSec into the Developer Workflow
Security

Claude Code Security Plugin: Pushing AppSec into the Developer Workflow

Anthropic shipped a security-guidance plugin for Claude Code that identifies and fixes vulnerabilities during coding. Available to all users via the plugin marketplace, not just Enterprise. Discusses whether this becomes a lightweight assistant, serious AppSec layer, or bridge to Claude Security.

OpenClawRadar
ClawSecure: Security Platform for OpenClaw Ecosystem with 3-Layer Audit and Real-Time Monitoring
Security

ClawSecure: Security Platform for OpenClaw Ecosystem with 3-Layer Audit and Real-Time Monitoring

ClawSecure is a dedicated security platform for OpenClaw that performs 3-layer security audits, real-time monitoring with SHA-256 hash tracking every 12 hours, and provides full OWASP ASI coverage. It has audited 3,000+ popular skills and is free to use with no signup required.

OpenClawRadar
Agent Isolation Security Analysis: From No Sandbox to Firecracker VMs
Security

Agent Isolation Security Analysis: From No Sandbox to Firecracker VMs

Analysis of how Cursor, Claude Code, Devin, OpenAI, and E2B isolate agent workloads, ranging from no sandbox to hardware-isolated Firecracker microVMs. Container runtimes have had escape CVEs annually since 2019, while Firecracker has zero guest-to-host escapes in seven years.

OpenClawRadar