CVE-2026-40068 — In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposit — CVE Database · The Intelligence Room