
CVE-2026-45033 の PoC。Github Copilot ではなく Claude Code 向け。Haiku 4.5 で動作確認済み。
core.fsmonitor ガード回避 (PoC)「悪意のあるベア git リポジトリ → core.fsmonitor → コード実行」 という脆弱性クラス (cf. GitHub Copilot CLI の CVE-2026-45033) に対する Proof-of-concept を、Claude Code に対して再現し、Copilot にはなかった Claude Code が追加した追加の bash 権限ガードを回避するものです。
結果: エージェントがガードを越えて植え付けられたファイルを持つリポジトリで git コマンドを実行すると、Claude Code のサンドボックス内でコード実行が発生します。ペイロードは無害です(/tmp/.bench-marker にタイムスタンプを書き込むだけ)。
Claude Code は、git 構造ファイル(HEAD/objects/refs/hooks)を作成し、かつ git を実行するような bash コマンドの前にプロンプトを表示します:
「このコマンドは git リポジトリ構造ファイル(HEAD/objects/refs/hooks)を作成し、その後 git を実行するため、作成されたファイルから hooks/fsmonitor を実行できる可能性があります。」
2 つの回避方法:
current -> . の場所に current/HEAD を書き込みます。旧ガードはパスを字句的に解決するため、HEAD を認識しません。(パッチ済みリリースの realpath 変更により修正済み)mkdir/touch/mv/cp)のみパスチェックします。/bin/mkdir、install、またはリポジトリに同梱されたバイナリはスキップされます。(パッチ済みリリースでも有効)いずれの場合も、プロジェクトディレクトリは有効なベアリポジトリとなり、その core.fsmonitor が次の git status で発火します。
2 つの構成要素:
container/ two Claude Code versions side by side, auto-updater disabled
malicious-repo/ a plausible monorepo that carries the injection
環境の健全性チェック(エージェントなし、メカニズムを証明):
cd malicious-repo
./build.sh
./verify.sh # clones fresh, runs the planted command, asserts fsmonitor fired
実際の Claude Code に対するライブテスト:
cd container
./build.sh # builds an image with both the vulnerable and patched versions
./run.sh login # one-time sign-in (shared across versions)
./run.sh # drops you in the malicious checkout; run claude and follow the prompt
ステップバイステップのライブ手順と、2 つのバージョン間の期待される差分については、malicious-repo/RUNBOOK.md を参照してください。
$HOME に到達できません。/tmp/.bench-marker へのタイムスタンプのみで、他には何もありません。
ネットワーク通信も、ファイル読み取りも、破壊的な操作もありません。