https://reddit.com/r/netsec/comments/1rz2xuw/claude_code_workspace_trust_dialog_bypass_via/: Claude Code workspace trust dialog bypass via repository settings loading order [CVE-2026-33068, CVSS 7.7]. Settings resolved before trust dialog shown.
Published Mar 20, 2026
·Updated
Affected Software
1 affected component
Anthropic Claude Code CLI<2.1.53
Frequently Asked Questions
1
What is the severity of CVE-2026-33068?
CVE-2026-33068 has a CVSS score of 7.7, indicating it is a high-severity vulnerability.
2
How do I fix CVE-2026-33068?
To mitigate CVE-2026-33068, update to Anthropic Claude Code CLI version 2.1.53 or later.
3
What type of vulnerability is CVE-2026-33068?
CVE-2026-33068 is a configuration loading order defect that allows bypassing the workspace trust dialog.
4
Which versions of Anthropic Claude Code CLI are affected by CVE-2026-33068?
CVE-2026-33068 affects all versions of Anthropic Claude Code CLI prior to version 2.1.53.
5
What can attackers achieve by exploiting CVE-2026-33068?
Exploiters can execute unauthenticated actions by bypassing the workspace trust confirmation dialog using a malicious settings file.