ACVEAgent configuration vulnerability registry

ACVE-2026-0434

Claude Code on macOS, opened on an untrusted repository with its sandbox enabled, ran a repository-controlled command outside the sandbox without a permission prompt.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

In the wild

demonstrated

Description

What

Accomplish demonstrated that Claude Code's macOS sandbox covered the Bash tool while the harness's git path remained outside it. An untrusted repository could therefore cause a command to run with the logged-in user's authority even in the strictest permission mode.

Detection

Accomplish includes a proof of concept and reports the fix in Claude Code 2.1.247.

Fix

Upgrade Claude Code to 2.1.247 or later and do not treat the sandbox as a complete boundary for untrusted repositories.

Fix

Upgrade Claude Code to 2.1.247 or later.

  • Upgrade harness:claude-code to 2.1.247. Anthropic fixed the issue in this version according to the report. Owner: operator

Report a problemJSON