{"uid":"cap_gh_w6trLH0v_qqSx9aLOL","slug":"tenjin-security-brief-claude-code-worktree-sandbox-escape-f2ce5b4c","name":"Tenjin Security Brief: Claude Code Worktree Sandbox Escape","description":"GitHub published a high-severity Claude Code advisory for a worktree path-confusion sandbox escape; @anthropic-ai/claude-code versions 2.1.38 through 2.1.162 should be treated as vulnerable unless auto-update has already moved them to 2.1.163 or later.","url":"https://tenjin.blog/api/read/security-briefs/security-briefs-daily-claude-code-patched-the-worktree-boundary","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_nsZcA8FZqdUS92XBgpvZv","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a paid security brief article about the high-severity Claude Code worktree path-confusion sandbox escape vulnerability (CVE patched in v2.1.163).","exampleAgentPrompt":"Pull up the Tenjin security brief on the Claude Code worktree path-confusion sandbox escape — I want to know which versions are affected and whether the patch is out yet.","exampleUseCases":[{"title":"Checking Claude Code vulnerability exposure","prompt":"Can you fetch the Tenjin security brief on the Claude Code worktree boundary sandbox escape? I need to know if versions in the 2.1.x range are affected and what I should upgrade to."},{"title":"Security team patch triage","prompt":"Get me the full Tenjin article on the high-severity Claude Code advisory GitHub published — specifically the worktree path-confusion issue — so I can figure out if our team's installs are patched."},{"title":"AI tooling security audit briefing","prompt":"Pull the Tenjin daily security brief covering the Claude Code worktree sandbox escape patch so I can include it in today's security roundup for our engineering leads."}],"resultDescription":"Returns the full text of a Tenjin security brief article detailing the high-severity Claude Code worktree path-confusion sandbox escape vulnerability, including affected version ranges (2.1.38–2.1.162), the patched version (2.1.163+), and GitHub advisory context. Response is gated behind a $0.10 USDC x402 micropayment.","failureModes":["Payment not included or invalid — x402 payment required before content is served","Slug or handle not found — 404 if the article path is incorrect","Article not yet published — may return empty or not-found if timing is off","Network timeout — upstream blog server unresponsive","Invalid path parameters — handle or slug malformed causing routing failure"],"whenToPreferThis":"Use this endpoint when you need the specific Tenjin security brief on the Claude Code worktree sandbox escape vulnerability (slug: security-briefs-daily-claude-code-patched-the-worktree-boundary). Prefer it over general web search when you want a structured, paid-quality security brief with curated context rather than raw GitHub advisory text or community commentary. Suitable for automated security pipelines that ingest Tenjin's daily briefs via x402 micropayments.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:34:54.484Z","isFirstParty":false}