Skip to main content

🪐 Backed by $16.5M to build the security workforce for the security workforce. Meet the new Cantina.

Vulnerability disclosure

Repository settings can skip the workspace trust prompt

CVE-2026-33068

Affected product
Claude Code
Severity
High
CVSS
8.8
Weakness
CWE-807
Published

Disclosure summary

CVE-2026-33068 is a high-severity CWE-807 vulnerability in Claude Code. Repository settings can skip the workspace trust prompt. Cantina reproduced the behavior, verified its security impact, and coordinated disclosure with the affected maintainer.

Verification standard

Cantina publishes a disclosure only after reproducing the behavior, validating its security impact, and coordinating remediation with the affected project.