ACVE-2026-0434
Claude Code on macOS, opened on an untrusted repository with its sandbox enabled, ran a repository-controlled command outside the sandbox without a permission prompt.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
demonstrated
Description
What
Accomplish demonstrated that Claude Code's macOS sandbox covered the Bash tool while the harness's git path remained outside it. An untrusted repository could therefore cause a command to run with the logged-in user's authority even in the strictest permission mode.
Detection
Accomplish includes a proof of concept and reports the fix in Claude Code 2.1.247.
Fix
Upgrade Claude Code to 2.1.247 or later and do not treat the sandbox as a complete boundary for untrusted repositories.
Fix
Upgrade Claude Code to 2.1.247 or later.
- Upgrade
harness:claude-codeto2.1.247. Anthropic fixed the issue in this version according to the report. Owner: operator