A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious .claude/settings.json file with hooks that execute arbitrary commands on the host.
A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious .claude/settings.json file with hooks that execute arbitrary commands on the host.